AWS Dogwood brings stateful authorization to AI agents. Learn how it fits with workload identity, AuthZEN, IAM, and the move away from long-lived credentials.
Today’s businesses spend more money on SaaS tools than on laptops. According to Gartner, the average organization now uses over 125 different SaaS applications. With the multitude of cloud apps businesses use on a daily basis, securing that expanding environment requires visibility and control across users, applications, data, and infrastructure.
Cloud adoption is no longer just a question of where workloads run. Managing a complex cloud environment without a unified view is like running a city with separate control rooms for every utility. While this is quite possible, it likely will be much slower and much harder to manage. In a similar way, the bigger challenge for IT Leaders is maintaining visibility, security, operational control, and evidence for compliance.
Cloud-native infrastructure was supposed to make security simpler. Instead, it multiplied the surface. Every container image brings its own packages, every Kubernetes cluster adds services and network policies, and every cloud account layers security groups, identities, and managed services on top. Scanners dutifully report thousands of vulnerabilities across all of it, many labeled critical, and the backlog grows faster than any engineering team can patch.
Is AI a "mass extinction event" for traditional software? In this insightful session from Brivo’s 2025 Cloud Security Summit, CEO Dean Drako and President Steve Van Till break down how artificial intelligence is disrupting tech and revolutionizing the physical security space. Learn how AI-driven tools—like real-time visual gun detection, natural language search, and hybrid cloud-edge architecture—are transforming safety protocols and making security platforms faster, smarter, and more scalable than ever before.
Migrating to the cloud brings data center challenges into the cloud. Some embrace a cloud-first approach, granting app teams control for speed. But how does the network keep up? Handling tens of thousands of security policies across cloud-native tech, SDNs, and SASE increases complexity and misconfiguration risks.
Twelve years ago, during Birthday Week 2014, we turned on Universal SSL and nearly doubled the number of encrypted sites on the web overnight, giving free TLS to every site behind Cloudflare, including the ones that never paid us a cent. Encryption stopped being an expensive, time-intensive undertaking and instead became the default. For Birthday Week this year, we are taking the next step on that path.
Learn how Agentic IAM helps organizations discover, secure, and govern AI agents throughout their lifecycle, giving IT the visibility and control needed to confidently manage a workforce of both humans and AI.
In 2023, Cloudflare declared itself free from CAPTCHAs with the launch of Turnstile, our privacy-first client-side challenge. Turnstile is free to use, works on any site (no need to proxy traffic through Cloudflare), and never asks a visitor to solve a puzzle. Now, we are launching Turnstile Spin, an agent-mediated end-to-end implementation of Turnstile.
On September 4, 2026, Oren Yomtov, a security researcher from Accomplish, responsibly reported a vulnerability affecting Cloudflare Containers and Cloudflare Sandboxes (which is built on Containers), through Cloudflare’s bug bounty program. Cloudflare has fully remediated the vulnerability, and we have no evidence that customer data has been compromised.
Within Netwrix Security Research, we were helping a customer with an Entra ID assessment and knew they'd already done AD tiering on-prem. We also knew they had domain controllers virtualized in Azure, but it was hard to tell which Windows Server was actually a DC. We figured out that Azure Run Command lets you run commands as SYSTEM, so we used that to do reconnaissance and identify the DCs.
Prioritization in CTEM is the process of determining which exposures should be addressed first based on the risk they pose in your specific environment. Rather than relying on severity scores alone, effective prioritization combines internal business and asset context with external threat intelligence, then focuses teams on the fixes that reduce the most meaningful risk.
Every mining cycle returns to the same unromantic question: what does one megawatt earn after the electricity bill? As hashprice narrows the margin on mining hardware, AI workloads offer power-rich operators another source of revenue. Bitdeer's move into full-stack AI Cloud is therefore less a change of identity than a change in how infrastructure gets paid.
In the cloud, an identity is no longer necessarily a person. It can be an application calling an API, a workload accessing storage, a service account running an automated process, or a machine interacting with another cloud resource. Each needs permissions to operate, and each becomes part of an access environment that changes as quickly as the infrastructure itself. This has expanded identity security beyond managing users and accounts to governing a much larger ecosystem of human and non-human access.
The digital world is growing faster than ever before. The security of sensitive information becomes increasingly critical as reliance on digital systems increases in business and daily life. Cybersecurity should not be a matter of merely deploying home-grown simple firewalls or installing basic antivirus. Security continues to be an arms race as attackers grow more sophisticated in their techniques, and more intelligent in their defense. The way you protect data has been radically changed by advanced technology today. Here is a closer look at how modern engineering is shaping the future of digital security.
When you hit play on a video, you don't think about the army of servers that rush to deliver it. But for anyone running a streaming platform, choosing a CDN (Content Delivery Network) is crucial. Latency, throughput, and cache-hit ratio can be the difference between smooth streaming and angry users smashing the refresh button. Here's a practical, human-friendly look at four heavyweights in the streaming space: Fastly, Akamai, Cloudflare, and AWS CloudFront.
The UK is in the middle of a data centre building boom. Government forecasts put AI capable capacity needs at 6GW by 2030, three times what exists today, while electricity demand from the sector is also expected to rise significantly.
Isolation is not the same thing as security. Ron Ben Yizhak from SafeBreach Labs presented this research at Black Hat USA and DEF CON: when Microsoft shipped Python in Excel, the code didn't run on a machine. It ran in an isolated container in Azure. So he asked the obvious question. How isolated is it, really? An isolated environment still has an attack surface. It just moves. See how Ron: If your teams are evaluating cloud-executed code features, this one is worth the full read—the methodology matters as much as the findings.
Netskope Skylight Agent Action Control is an inline security capability within the Netskope Skylight AI Security suite designed to evaluate, govern, and enforce real-time controls over the actions performed by autonomous AI agents. Rather than simply blocking or allowing an entire AI application or coding assistant, it intercepts attempted agent operations—such as code pushes, database modifications, or API calls—before they execute.
A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with analytics, or asking a remote server what to execute next. Pages load, products appear, and checkout works — yet the browser may be quietly doing something the site owner never authorized. That is the blind spot our Client-Side Security machine learning (ML) model is built to expose.
CTEM Discovery is about more than finding assets. It’s about understanding what exists, what’s actually being scanned, and how data from different tools connects. Seemplicity correlates security, inventory, identity, and ownership data across sources to create a unified view of each asset, expose coverage gaps, and give security teams the context they need to prioritize, validate, and remediate exposures effectively.
Your business almost certainly runs on cloud services. From document storage, email and finance software to your customer data and internal systems, the chances are that most of what keeps your business operational lives, at least in part, in the cloud. And yet, for many businesses, the question of whether that cloud environment is secure rarely gets asked. It tends to be presumed. After all, you’ve got bigger things to worry about. You’re with a reputable provider.
Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke risky file shares and dispatch custom webhooks, without manual intervention. When we launched Cloudflare CASB, a cloud access security broker, we wanted to provide security teams complete visibility into the posture of their SaaS applications before misconfigurations became incidents.
A math function in Excel became a path to root in Microsoft's cloud. SafeBreach Labs researcher Ron Ben Yizhak reverse-engineered the isolated Azure containers behind Microsoft's Python in Excel feature—and found the "isolated" part didn't fully hold. Cloud isolation claims are a trust boundary. Trust boundaries get tested. What he found: Both issues were responsibly disclosed to Microsoft and patched between March and June 2026, and the research debuted at DEF CON 34.
As cloud tech evolves, managing hybrid and multi-cloud environments brings new security challenges. How do we maintain visibility and control across diverse vendors and traditional tools now in the cloud? The key is agile orchestration with corporate guardrails.
AlgoSec rebrands from firewall management to a product-as-a-platform, launching Horizon. This new platform simplifies deployment and values applications driving connectivity across any security device.
1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardized by the National Institute of Standards and Technology (NIST). This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure. Cloudflare plans to achieve full post-quantum security by 2029. Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC.
Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest, we start over, and the connection costs two round trips.
Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense. Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their codebases.
Why do data breaches still happen when companies are running five, 10, sometimes 15 different data security tools? In this episode of Ask SME Anything, our expert Ankur Chadda breaks down why more tools don't mean more visibility, and how Netskope One DataSec Command Center brings inline traffic, API scans, posture management, and other data security tools into a single view.
For years, managed service providers (MSPs) have secured customer cloud environments through periodic reviews of each tenant. That approach worked when a customer ran two or three cloud applications. As organizations adopt more SaaS applications, the number of environments, identities, and configurations to monitor also increases. The challenge is already visible.
Email remains the primary entry point for cyberattacks, making effective email security more critical than ever. That’s why we’re especially proud that customers ranked Acronis Cyber Protect Cloud in the G2 Fall 2026 Cloud Email Security Grid Report. Because G2 rankings are based on verified customer reviews, this recognition reflects the experience of the organizations and service providers that rely on Acronis to protect their users, data and business communications every day.
You can reduce your cloud attack surface by auditing every persistent permission across your cloud and identity platforms, stripping away unnecessary access and replacing always-on admin rights with Just-In-Time (JIT) access that’s granted on approval, time-limited and automatically revoked. Getting there starts with understanding why standing privilege makes up such a significant portion of the cloud attack surface.