San Francisco, CA, USA
2009
  |  By CASB
Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke risky file shares and dispatch custom webhooks, without manual intervention. When we launched Cloudflare CASB, a cloud access security broker, we wanted to provide security teams complete visibility into the posture of their SaaS applications before misconfigurations became incidents.
  |  By 1.1.1.1
1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardized by the National Institute of Standards and Technology (NIST). This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure. Cloudflare plans to achieve full post-quantum security by 2029. Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC.
  |  By Application Security
Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest, we start over, and the connection costs two round trips.
  |  By Artificial Intelligence
Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense. Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their codebases.
  |  By Application Security
Modern bot threats are increasingly driven by determined, sophisticated attackers. Often it is not even one person, but a group trading techniques with each other or a commercial service sold to anyone willing to pay. For many of them, getting past bot detection is a full-time job they genuinely enjoy. Block them and they get to work, finding a workaround. AI has simplified this further, making it even easier to set up complex configurations for attackers, lowering the overhead of an attack.
Since June, developers have created thousands of third-party OAuth apps on Cloudflare, with more than a million authorizations since. OAuth makes delegated access possible. It lets applications act on a user’s behalf without asking them to handle long-lived credentials or hand over a password. That model works well when an application can describe its access needs with a small set of scopes. Developers use OAuth for SaaS integrations, internal tools, CLIs, and agents.
  |  By Martin Schwarzl and Albert Pedersen
In 2021, we assessed remote Spectre attacks against Cloudflare Workers. Based on the results, we shipped a production defense called Dynamic Process Isolation (DyPrIs), which identifies maliciously looking scripts and isolates them into separate processes. Since then, newer techniques in the area of stabilizing Spectre attacks have been discovered. To understand if these techniques posed a threat to our Workers production environment, we decided to internally reassess the remote Spectre attack.
Route leaks push traffic down paths it was never meant to take. We have written and spoken publicly in the past about route leaks in Border Gateway Protocol (BGP), depicting these events as impactful incidents that cause misdirection of traffic through unintended network paths. BGP routing is driven by the relationships between Autonomous Systems (ASes), i.e., customer-provider and peer-peer.
AI has enabled employees across every team to build applications faster than ever before. But that speed is also what's keeping every CISO up at night: any employee can build an application, deploy it to the public Internet, and accidentally expose internal work or company data. Today, we're launching new tools to make it easy to keep your applications hosted on Workers private.
  |  By AJ Gerstenhaber and Kenny Johnson
Most companies designed their resource permissions with a human user in mind. A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access. Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed.
  |  By Cloudflare
As cyber threats become more sophisticated, strategic partnerships are essential for robust defense. In this interview, we sit down with the team at SentinelOne to discuss how our integrated solutions provide end-to-end security for the modern enterprise.
  |  By Cloudflare
Oron Noah, VP of Product Extensibility & Partnership at Wiz, shares how the Cloudflare and Wiz partnership began and how their integration delivers better security outcomes — from code to production — by giving every team full visibility into their cloud environment.
  |  By Cloudflare
Check out this special video where we heard from Trey Guinn, one of our long-time Cloudflare volunteers who worked directly with organizations protected under Project Galileo.
  |  By Cloudflare
In this Women of Cloudflare segment, Cita James, Manager, People Team Business Partner at Cloudflare, shares her journey from Oklahoma City to Cloudflare’s People Team, working across Austin, Lisbon, London, and the EMEA region.
  |  By Cloudflare
How does your computer actually find data? JQ Lau from Cloudflare's hardware team explains the difference between CPU cache and memory with a simple analogy — and why it matters when you're designing servers for millions of requests.
  |  By Cloudflare
In this episode of This Week in NET, JQ Lau and Victor Hwang from our Network & Infrastructure Strategy team walk us through Cloudflare's 13th generation of servers — the machines that power a significant part of the internet across 330+ cities worldwide. The Gen 13 program doubled compute density by jumping from 96 to 192 cores, but that came with an 83% drop in L3 cache. The team explains how a bold hardware bet, combined with Cloudflare's FL2 Rust-based software rewrite, turned that trade-off into a win across throughput, latency, and power efficiency.
  |  By Cloudflare
In this episode of This Week in NET, Vinti Batiste, VP of Sales for US Enterprise at Cloudflare, shares her 30-year journey across IBM, Cisco, and now Cloudflare — and what it really means to be in enterprise sales. Vinti talks about growing Cloudflare's enterprise business 80% year over year, the moment Michelle Zatlyn walked into her first all-hands, how she uses AI to prepare for customer meetings, and why sales is really a math problem.
  |  By Cloudflare
Join Thomas Gauvin, Senior Product Manager, as he discusses the launch of Cloudflare Email Service in public beta, providing the essential infrastructure for agents to communicate via email. Tune in to learn about these three major updates.
  |  By Cloudflare
As cyber threats become more sophisticated, strategic partnerships are essential for robust defense. In this interview, we sit down with the team at SentinelOne to discuss how our integrated solutions provide end-to-end security for the modern enterprise.
  |  By Cloudflare
The conversation explores why the Internet and the cloud were not designed for an AI-agent world, and what infrastructure needs to change as software agents begin generating code, running workflows, and interacting directly with online services. Ming and Anni walk through several announcements from Cloudflare’s Agents Week, including new tools for agent infrastructure, memory, developer workflows, AI Gateway, email, artifacts, browser automation, security, and agent-ready websites.
  |  By Cloudflare
This whitepaper discusses the many challenges that DNS providers and users face including massive cyber attacks as well as performance and reliability issues, and how Cloudflare can help resolve these challenges, ensuring business continuity.
  |  By Cloudflare
Strategies for preventing data breaches, shadow APIs, abuse, and other common challenges.
  |  By Cloudflare
Organizations are facing economic uncertainty as the outlook grows more unpredictable. This uncertainty - often exemplified by shrinking budgets - puts pressure on CIOs and technical leaders to find new paths forward.
  |  By Cloudflare
Learn how Cloudflare is able to stop some of the most sophisticated DDoS attacks.
  |  By Cloudflare
This whitepaper discusses the growth of large scale DDoS attacks, how these attacks target as well as leverage DNS provider infrastructures, and how Cloudflare can help protect your business against the impact of such massive attacks.
  |  By Cloudflare
Growing a startup requires delivering excellent online experiences. In this guide, we share tips to help startups create the kind of high-performing, reliable, and secure websites and applications needed to do so.

Cloudflare is a global network designed to make everything you connect to the Internet secure, private, fast, and reliable.

Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare have all traffic routed through its intelligent global network, which gets smarter with each new site added. As a result, they see significant improvement in performance and a decrease in spam and other attacks.

The Integrated Global Cloud Network:

  • Zero Trust Services: Stop data loss, malware and phishing with the most performant Zero Trust application access and Internet browsing solution.
  • Website & App Performance: Speed up websites, apps, & APIs through our global network to optimize your content & deliver it closer to the users location.
  • Website & App Security: Protect websites & applications from bots, DDoS attacks & more. All while monitoring for suspicious activity & potential attacks.
  • Network Security & Performance: Networking solutions to connect, secure, & accelerate your networks — without the cost & complexity of managing legacy hardware.
  • Developer Platform: Deploy serverless code instantly across the globe to give it exceptional performance, reliability, & scale.
  • SASE - Cloudflare One: Zero Trust network-as-a-service platform to dynamically connect remote & on-site users to resources, with identity-based security controls.

A global network built for the cloud.