Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

April 2023

SLP: a new DDoS amplification vector in the wild

Earlier today, April 25, 2023, researchers Pedro Umbelino at Bitsight and Marco Lux at Curesec published their discovery of CVE-2023-29552, a new DDoS reflection/amplification attack vector leveraging the SLP protocol. If you are a Cloudflare customer, your services are already protected from this new attack vector.

Secure by default: recommendations from the CISA's newest guide, and how Cloudflare follows these principles to keep you secure

When you buy a new house, you shouldn’t have to worry that everyone in the city can unlock your front door with a universal key before you change the lock. You also shouldn’t have to walk around the house with a screwdriver and tighten the window locks and back door so that intruders can’t pry them open.

Cloudflare One named in Gartner Magic Quadrant for Security Service Edge

Gartner has recognized Cloudflare in the 2023 “Gartner® Magic Quadrant™ for Security Service Edge (SSE)” report for its ability to execute and completeness of vision. We are excited to share that the Cloudflare Zero Trust solution, part of our Cloudflare One platform, is one of only ten vendors recognized in the report. Of the 10 companies named to this year’s Gartner® Magic Quadrant™ report, Cloudflare is the only new vendor addition.

8 - Advanced

In this session, we will dive into the advanced usage of Zaraz. We will cover how you can use Zaraz to run data transformation/enrichment on the Edge using Workers Variables. Additionally, we will discuss the HTTP request tool and how you can use it for ETL/monitoring/marketing automation. Lastly, we will cover Zaraz's HTTP Events API, which lets you send data to Zaraz from any potential source over HTTP.

9 - Testing & Debugging

In this session, we will dive into the advanced usage of Zaraz. We will cover how you can use Zaraz to run data transformation/enrichment on the Edge using Workers Variables. Additionally, we will discuss the HTTP request tool and how you can use it for ETL/monitoring/marketing automation. Lastly, we will cover Zaraz's HTTP Events API, which lets you send data to Zaraz from any potential source over HTTP.

DDoS threat report for 2023 Q1

Welcome to the first DDoS threat report of 2023. DDoS attacks, or distributed denial-of-service attacks, are a type of cyber attack that aim to overwhelm Internet services such as websites with more traffic than they can handle, in order to disrupt them and make them unavailable to legitimate users. In this report, we cover the latest insights and trends about the DDoS attack landscape as we observed across our global network.