Sign in

The Cloudflare Blog [Unofficial]

@blog.cloudflare.com.web.brid.gy
150 followers 0 following 988 posts

Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. 🌉 bridged from 🌐 blog.cloudflare.com: fed.brid.gy/web/blog.cloudflare.com

PostsRepliesMedia
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14h
blog.cloudflare.com
Cloudflare Impact reaches $100 million in donations
This week, Cloudflare's Impact programs will reach $100 million in donated services. This milestone means that thousands of entities including journalists, civil society, state and local governments, election management bodies, and public schools are being protected from cyberattacks.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14h
blog.cloudflare.com
Identify AI model overuse with User Insights
AI Gateway User Insights now adds task, model, turn, and user categories to help teams understand AI adoption and make better model decisions. This is available free to AI Gateway users.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14h
blog.cloudflare.com
The Internet has a second audience
More than half the traffic reaching sites on Cloudflare is now automated, and AI agents are the fastest-growing part of it. We're giving site owners the tools to see who's visiting, decide who gets in, and charge for access.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 29/09/2026
blog.cloudflare.com
Preventing quantum downgrade attacks against IPsec
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to prevent these attacks.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026
blog.cloudflare.com
Next.js applications, powered by Vite: introducing Vinext 1.0
Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026
blog.cloudflare.com
Introducing cf: the agentic CLI for the entire Cloudflare API
We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026
blog.cloudflare.com
How fast is the web? Explore billions of real-user measurements with BEACON
Cloudflare is open-sourcing the BEACON dataset, making billions of anonymized Real User Monitoring (RUM) performance records publicly available on Google BigQuery. Explore real-world Core Web Vitals, soft navigation metrics, and performance breakdowns across browsers and regions.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026
blog.cloudflare.com
Supporting native Rust in Workers with the new Emscripten target for wasm-bindgen
With the new experimental support for the Emscripten target in Rust Workers, many previously unsupported Rust libraries and applications can now be built and deployed directly to Cloudflare’s global Workers platform, including upcoming support for Tokio async.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 27/09/2026
blog.cloudflare.com
Cloudflare’s 2026 Annual Founders’ Letter
The Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new creators, and how we can help build a fair, sustainable future for the web.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 25/09/2026
blog.cloudflare.com
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 24/09/2026
blog.cloudflare.com
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 22/09/2026
blog.cloudflare.com
We just shipped support for the ugliest part of HTTP: Vary
Vary support is now available in Cache Rules on every plan. You can normalize known negotiation headers, pass exact values through to the origin when those small differences matter, or bypass cache when the variation is too unpredictable.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 22/09/2026
blog.cloudflare.com
Introducing Worker Previews: Isolated preview environments for every change your agent makes
Worker Previews gives every branch its own URL, configuration, state, and observability, so you and your agents can test changes in parallel without affecting production.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 18/09/2026
blog.cloudflare.com
Saving another 100TB of RAM with math (and Rust)
Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one of our Pingora-based service's RAM usage with statistics.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 16/09/2026
blog.cloudflare.com
When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 15/09/2026
blog.cloudflare.com
Give every teammate and agent the right level of access to your Workers
You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 11/09/2026
blog.cloudflare.com
Introducing automatic remediation policies with Cloudflare CASB
Cloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven logic to revoke risky file shares and send webhooks without manual intervention.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 10/09/2026
blog.cloudflare.com
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 09/09/2026
blog.cloudflare.com
How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility
Workers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with import.meta, lazy compilation, shared code caches, and clearer errors.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 08/09/2026
blog.cloudflare.com
Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, preferring post-quantum connections wherever the origin supports it.
001
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 03/09/2026
blog.cloudflare.com
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 01/09/2026
blog.cloudflare.com
How we could save petabytes of cache storage with Zstandard and Pingora
Could we get more cache space with the same hardware? We prototyped compression inside Cloudflare's cache to find out.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 31/08/2026
blog.cloudflare.com
Introducing Adaptive Intelligence: Undermining the economics of every bot attack
Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from the meta-signals of live traffic and deploying disposable rules, making automated attacks too expensive to sustain.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/08/2026
blog.cloudflare.com
BotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents
Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission editing, and a behavior model so operators can accurately declare how their bots use content.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 24/08/2026
blog.cloudflare.com
The Cloudflare Blog – Brought to you by EmDash
We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 22/08/2026
blog.cloudflare.com
Say it once: introducing Bot Preference Sync
Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 20/08/2026
blog.cloudflare.com
From all-or-nothing to task-based OAuth consent
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.
010
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 19/08/2026
blog.cloudflare.com
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 18/08/2026
blog.cloudflare.com
BGP Role model: tracking the adoption of RFC 9234
RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14/08/2026
blog.cloudflare.com
How Cloudflare detects MCP traffic and helps secure it
Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for approved servers, and block direct connections on managed network paths.
010
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14/08/2026
blog.cloudflare.com
Secure all your internal vibe-coded applications — in one click
Introducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs — routes, custom domains, workers.dev, and previews — automatically.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 13/08/2026
blog.cloudflare.com
Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal
Cloudflare's data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality of the total solar eclipse that occurred on August 12, 2026.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 13/08/2026
blog.cloudflare.com
Certificate Transparency Monitoring is now generally available
Cloudflare's Certificate Transparency Monitoring is now generally available. The biggest change: we no longer email you about certificates Cloudflare issued for your domain, so when an alert lands in your inbox, it's worth a look.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 11/08/2026
blog.cloudflare.com
Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.
010
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 10/08/2026
blog.cloudflare.com
Everything we launched during Agents Week
Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 10/08/2026
blog.cloudflare.com
Serving the most critical missions: Cloudflare for Government achieves FedRAMP Class D (High) Certified status
Cloudflare for Government achieves FedRAMP Class D (High) Certified status. We also announce our commitment to pursue DoD IL4 authorization. Cloudflare brings world-class security, performance, and developer products to the public sector.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 07/08/2026
blog.cloudflare.com
Unveiling good and bad behaviors on the Agentic Internet
Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 07/08/2026
blog.cloudflare.com
Unifying Workers AI and AI Gateway into a single AI control plane
Cloudflare is unifying AI Gateway and Workers AI into a single control plane, giving developers observability, billing, and dynamic routing across both managed GPUs and external providers. Learn how unified bindings and model-first routing simplify building resilient AI applications.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 06/08/2026
blog.cloudflare.com
Give any website a WebMCP interface
Today we're launching a developer preview of WebMCP on Cloudflare. With one switch, any site becomes usable by browser AI agents — no new APIs, no origin changes — while the human stays in control and creators keep their traffic.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 06/08/2026
blog.cloudflare.com
Cloudflare is the only vendor named a Visionary in 2026 SASE and SSE reports
We're honored to announce that Cloudflare is the only vendor that has been recognized as a Visionary in both the 2026 Gartner® Magic Quadrant™ for SASE Platforms and the 2026 Gartner® Magic Quadrant™ for Security Service Edge reports.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 05/08/2026
The Agent Access Model proposes a new architecture to secure task-scoped agents using strict identity brokering, continuous mediation, and stateful trust.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 05/08/2026
blog.cloudflare.com
How we’re rethinking work at Cloudflare with Cloudflare OS
We built Cloudflare OS to equip our teams to safely rethink how they get work done with AI. The platform brings together the best of our technologies, from our Compute primitives to our Zero Trust suite. This post walks through our journey to give our users the best AI tools available.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 05/08/2026
blog.cloudflare.com
Cloudflare OS: an open platform for agents, apps, and work
Cloudflare OS is an open-source platform that lets everyone in your company build apps, automate work, and safely access internal systems, shaped around what your organization knows and how it operates
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 04/08/2026
blog.cloudflare.com
How we built a software factory to drive Astro’s GitHub issue count to zero
By replacing manual issue verification with isolated AI subagents running in GitHub Actions, the Astro maintainers reduced open issue count by 85%. This post explores the architecture behind automated bug reproduction, patch verification, and preview releases.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 03/08/2026
blog.cloudflare.com
Your agent needs a computer, not a container — introducing @cloudflare/computer
Agents need more than just a container to scale. We're introducing @cloudflare/computer, an agent runtime that dynamically orchestrates between fast, efficient isolates and full Linux containers to give every agent a computer of its own.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 03/08/2026
blog.cloudflare.com
Workers RPC now works across Python and JavaScript
One coding agent can write a Python Worker and another can write a JavaScript Worker. At runtime, those Workers can exchange references to live objects and call their methods without defining APIs, schemas, or serialization code
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 02/08/2026
blog.cloudflare.com
Welcome to Agents Week
Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 31/07/2026
blog.cloudflare.com
An API for MoQ: provision your own isolated relays
Last year we made every Cloudflare server a Media over QUIC (MoQ) relay. Now the new provisioning API lets you create your own isolated relay and control who can publish and who can only watch.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 30/07/2026
blog.cloudflare.com
Dogfooding at scale: migrating cdnjs to Cloudflare’s Developer Platform
We moved cdnjs, serving 9 billion requests a day, entirely onto Cloudflare's Developer Platform. That means we’re running one of the Internet's busiest open-source CDNs on our own building blocks, and we pushed Workflows and Workers limits higher for everyone.
000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 29/07/2026
blog.cloudflare.com
Post-quantum authentication to origins is now supported
Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providing PQ authentication for all Cloudflare products.
000