#security

12 articles

Cloudflare's Cloudy AI: Translating Complex Security Alerts into Actionable Human Guidance for Enhanced Enterprise Resilience
資安

Cloudflare's Cloudy AI: Translating Complex Security Alerts into Actionable Human Guidance for Enhanced Enterprise Resilience

Cloudflare's Cloudy AI agent leverages Large Language Models (LLMs) to transform complex security detection outputs into clear, actionable guidance, significantly boosting the response efficiency of enterprise security teams and end-users. This innovation not only reduces false positives and investigation burdens but also provides instant, contextual insights in email security and Cloud Access Security Broker (CASB) domains, heralding a new era of intelligent security management.

Passkey Security Alert: Why It Should Not Be Used for Encrypting User Data
資安

Passkey Security Alert: Why It Should Not Be Used for Encrypting User Data

Identity expert Tim Cappalli warns against using passkeys for encrypting user data, emphasizing their role in phishing-resistant authentication. Misusing passkeys for encryption could lead to irreversible data loss if users lose their passkeys, posing a severe threat to user trust and data security.

Cloudflare's Evolved Threat Intelligence Platform: Real-time, Proactive Defense at the Edge with ETL-less Architecture
資安

Cloudflare's Evolved Threat Intelligence Platform: Real-time, Proactive Defense at the Edge with ETL-less Architecture

Cloudflare unveils its evolved Threat Intelligence Platform (TIP), leveraging a unique ETL-less, sharded edge computing architecture with GraphQL and SQLite on Durable Objects. This platform fundamentally addresses the long-standing 'data gravity' problem in cybersecurity, integrating global telemetry with human analysis to empower security teams with sub-second, real-time insights and automated defense capabilities, transforming reactive security into proactive threat hunting.

Major Law Enforcement Operation Dismantles Tycoon 2FA Phishing-as-a-Service Platform: A Deep Dive into 2FA Bypass Threats and International Cooperation
資安

Major Law Enforcement Operation Dismantles Tycoon 2FA Phishing-as-a-Service Platform: A Deep Dive into 2FA Bypass Threats and International Cooperation

Europol has spearheaded a large-scale international law enforcement operation, successfully dismantling Tycoon 2FA, a sophisticated Phishing-as-a-Service (PhaaS) platform designed to bypass two-factor authentication (2FA). Over 330 malicious domains were seized, highlighting the critical role of international collaboration and advanced defensive strategies against evolving cyber threats.

Cloudflare's Truly Programmable SASE: Reshaping Enterprise Security at the Edge
資安

Cloudflare's Truly Programmable SASE: Reshaping Enterprise Security at the Edge

Cloudflare is redefining Secure Access Service Edge (SASE) with a platform that goes beyond traditional API integrations, offering true programmability at the edge. By deeply integrating its SASE and Developer Platforms on a global network, Cloudflare enables organizations to implement real-time, custom security logic, offering unprecedented flexibility and efficiency in safeguarding digital assets.

Google Chrome Emergency Update: Patching Ten Security Vulnerabilities, Enhancing Global User Browsing Security
資安

Google Chrome Emergency Update: Patching Ten Security Vulnerabilities, Enhancing Global User Browsing Security

Google recently released an emergency security update for its Chrome browser, patching up to ten security vulnerabilities across Windows, macOS, and Linux platforms, including several high-severity flaws. This move once again highlights the severe cybersecurity challenges faced by modern browsers as the core of digital life and emphasizes the importance of timely user updates to counter increasingly sophisticated online threats.

ASPA: A New Era of Internet Routing Security with Path Validation
資安

ASPA: A New Era of Internet Routing Security with Path Validation

The Border Gateway Protocol (BGP), the backbone of the Internet, is vulnerable to route leaks and hijacks. To address this, the industry is adopting ASPA (Autonomous System Provider Authorization), a new standard that cryptographically validates the entire path of network traffic. ASPA complements existing RPKI mechanisms to enhance Internet stability and security by preventing misdirection of traffic.

Cloudflare Radar Enhances Security Transparency: Post-Quantum Encryption, E2EE Messaging, and Routing Security Upgraded
資安

Cloudflare Radar Enhances Security Transparency: Post-Quantum Encryption, E2EE Messaging, and Routing Security Upgraded

Cloudflare has introduced significant enhancements to its Radar platform, boosting transparency across post-quantum encryption, end-to-end encrypted messaging, and internet routing security. These new tools expand monitoring for post-quantum encryption to origin-facing connections, provide a real-time key transparency audit dashboard for E2EE services, and deepen the tracking of ASPA adoption for BGP routing security, laying a stronger foundation for the future of internet security.