2025 cloud security roundup: How attackers abused identities, supply chains, and AI

In 2025, many of the long-standing cloud security concerns remained, but new areas of focus also developed. The significant increase in AI adoption enabled organizations to deliver features faster but also introduced new attack surfaces, such as untrusted or unpredictable user input for large language model (LLM) applications. At the same time, long-lived credentials and vulnerabilities in third-party packages continued to expose cloud environments to risk.

Scaling Globally? Use Argo Smart Routing to Cut Latency for Users Worldwide

Routing is the process of selecting the best path for data to travel across a network to its destination. But what if routing could be smarter and faster? Enter Cloudflare Smart Shield + Argo Smart Routing, which optimizes data paths to enhance both speed and reliability. Discover what smart routing is and how it can revolutionize your network performance: Key benefits of Argo Smart Routing: Want to dive deeper into routing and smart routing? Explore these resources in Cloudflare’s Learning Center.

Ransomware Remediation Tactics That Help You Recover Fast

Ransomware attacks have grown stronger in the last few years. Attackers are now stealing data before locking it. They also pressure victims by posting stolen files on the internet. There are groups that sell ransomware kits, making these attacks easy to run. This has made things worse for businesses all around the world. Teams are looking for ransomware remediation tactics that help them recover fast and reduce the chance of the attacker returning.

The Zero-Markup Domain: Transfer Your Domain to Cloudflare for Price and Security

Are you tired of rising domain renewal costs and sneaky WHOIS privacy fees? Unlike other registrars that mark up renewal costs, Cloudflare charges you ZERO markup, passing wholesale pricing directly to you. Top 3 Reasons to Transfer: Wholesale Pricing: No markup, ever. You pay what Cloudflare pays. Unbreakable Security: Free WHOIS Privacy and advanced domain locking. Seamless Integration: Instant access to Cloudflare's global CDN and DNS infrastructure.

The 2025 Cloudflare Radar Year in Review: The rise of AI, post-quantum, and record-breaking DDoS attacks

The 2025 Cloudflare Radar Year in Review is here: our sixth annual review of the Internet trends and patterns we observed throughout the year, based on Cloudflare’s expansive network view.

Arctic Wolf Observes Malicious SSO Logins on FortiGate Devices Following Disclosure of CVE-2025-59718 and CVE-2025-59719

In December 12, 2025, Arctic Wolf began observing intrusions involving malicious SSO logins on FortiGate appliances. Fortinet had previously released an advisory for two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719) on December 9, 2025. Arctic Wolf had also sent out a security bulletin for the vulnerabilities shortly thereafter.

CrowdStrike Leads the Way in the 2025 MITRE ATT&CK Enterprise Evaluations

The results of the 2025 MITRE ATT&CK Enterprise Evaluations are in and CrowdStrike excelled, achieving 100% detection, 100% protection, and zero false positives. The MITRE ATT&CK evaluation is an independent assessment that tests how cybersecurity products detect and stop real-world adversary behavior. The 2025 round was the most challenging cross-domain evaluation to date, a true platform test. For the first time, MITRE tested defenses across endpoint, identity, and cloud.

Microsoft Office 365 MFA Setup: What Admins Need to Know

In November 2024, Microsoft announced that multi-factor authentication (MFA) would become mandatory for all administrator accounts across Microsoft 365 (formerly Office 365), Azure, and Intune. Starting in 2025, admins without MFA enabled will no longer be able to access Microsoft’s admin portals. This rollout is happening in phases at the tenant level, and administrators who haven’t yet configured MFA will need to update their settings to stay compliant.