Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Learn more about building with Cloudflare - with Craig Dennis

As part of our "This Week in NET" show/podcast, Craig Dennis, Developer Educator at Cloudflare, walks us through Workers — our developer platform — and some of the things both developers and non-developers can build with it. A few highlights ahead of Developer Week (April 7–11, 2025), where new features and tools — including AI and AI agents — will be announced.

Master SaaS Security: Unifying Visibility & Control with Cato CASB

Shadow IT. Data leaks. Compliance violations. If your users are accessing cloud apps from unmanaged devices or outside sanctioned workflows, would you even know? In this video, we introduce Cato CASB (Cloud Access Security Broker), a native capability of the Cato SASE Cloud platform. Watch how Cato CASB provides deep real-time visibility into SaaS usage—both sanctioned and unsanctioned—so security teams can detect risky behavior, enforce access policies, and prevent data loss.

Cloudflare's commitment to CISA Secure-By-Design pledge: delivering new kernels, faster

As cyber threats continue to exploit systemic vulnerabilities in widely used technologies, the United States Cybersecurity and Infrastructure Agency (CISA) produced best practices for the technology industry with their Secure-by-Design pledge. Cloudflare proudly signed this pledge on May 8, 2024, reinforcing our commitment to creating resilient systems where security is not just a feature, but a foundational principle.

RBAC in ManageEngine CloudSpend: Empowering teams with secure access

Let’s think about a scenario where an IT operations team needs to track cost anomalies but does not require access to budget configurations or administrative settings. They have to go through the ticketing process to get sufficient access. Managing access to cost data and ensuring the right stakeholders have the appropriate permissions becomes a challenge.

Agentic AI Security Isn't Just A Technical Problem - It's a Strategic One

If you’ve started exploring how to secure AI agents in your environment (or even just reading about it), you likely already know that it’s not as straightforward as applying traditional AppSec practices. AI agents aren’t just another workload or API to monitor, they’re dynamic, semi-autonomous entities operating at the intersection of user intent, agent behavior, and enterprise systems. And not all AI agents are created equal or secure.

Honoring Dave Täht and his contributions to a better Internet (video calls included)

Dave Täht died this week (August 11, 1965 – April 1, 2025), and Tom Strickx, Principal Network Engineer at Cloudflare, honors his contributions to help build a better Internet. Dave Täht was an American network engineer, musician, lecturer, asteroid exploration advocate, and Internet activist. Without his work, FQ-CoDel wouldn't exist — and low-latency networking, from Wi-Fi to Starlink and video calls, would likely be worse today.

What is IoT Security?

Security measures aren’t keeping pace with the rate at which new technology is going to market. One of the fastest-growing segments of technology, the Internet of Things (IoT) — which includes webcams, smart thermostats, wearable health trackers, and other smart objects — is capturing the industry’s attention and growing rapidly. By 2030, the number of connected IoT devices is expected to grow to 40 billion.

Put AI to work where workflows work best

In this guest post, Jason English, Director and Principal Analyst at Intellyx explores how GenAI is moving beyond chat to orchestrate real action for SOC teams. As my colleague Eric Newcomer mentioned in the previous chapter of this series, GenAI changes the security automation game, with multi-system discovery, documentation, and task execution capabilities that can reduce cognitive load and toil for security analysts.

API Attacks Up 150% - Here's Why You Should Care Now #APISecurity #APIAttacks #AIVulnerabilities

Even worse, 98.9% of AI vulnerabilities are tied to insecure APIs.. APIs are being discovered in under 30 seconds, according to Wallarm’s honeypot research. Weak authentication, broken access controls, and missing rate limits are opening the door. Now’s the time to take API security seriously. Learn how to protect your systems before it’s too late.

Unmasking EncryptHub: Help from ChatGPT & OPSEC blunders

This is the second part of Outpost24’s KrakenLabs investigation into EncryptHub, an up-and-coming cybercriminal who has been gaining popularity in recent months and is heavily expanding and evolving operations at the time of writing. We’ve already published one article explaining EncryptHub’s campaigns and TPPs, infrastructure, infection methods, and targets.