Welcome to Agents Week | The Cloudflare Blog
This week is Agents Week. As we started thinking about and planning the week, we wrestled with a broader question of what it means to…
This week is Agents Week. As we started thinking about and planning the week, we wrestled with a broader question of what it means to…
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine.…
AI systems moved from experimental risk to confirmed attacker, a Cisco firewall zero-day was actively exploited in the wild, and a critical VMware authentication bypass…
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan. Documented by…
Swati KhandelwalJul 31, 2026Artificial Intelligence / Cyber Attack Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent…
The way AWS S3 works has become the de facto standard for object storage in many cloud environments outside of AWS. It can be surprising…
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty Programs (BBPs). The update,…
Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique…
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks Pierluigi Paganini August 02, 2026 After attacks hit 30+ Minnesota water systems, CISA urged utilities…
The security benefits of multifactor authentication (MFA) are well-known, yet MFA continues to be poorly, sporadically, and inconsistently implemented, undercutting its effectiveness as a security tool while…
As organizations scale in the cloud, managing identities and access becomes increasingly complex. Every new service, application, and role adds more permissions, and without proper…
A significant data breach has hit SplitVPN, a Russian VPN provider formerly known as NotVPN, exposing the personal records of roughly 865,000 unique users. The…