厂商发布
厂商对产品安全、配置或策略的更新说明。
-
Scaling Security Insights: how we achieved a 10x increase in global scanning capacity
Cloudflare Security Insights system now processes over 120 scans per second, providing frequent insights for all customers. By optimizing Kafka consumers, Postgres queries, and our API, we scaled our throughput 10x without adding hardware.
Cloudflare Security Insights system now processes over 120 scans per second, providing frequent insights for all customers. By optimizing Kafka consumers, Postgres queries, and our API, we scaled our throughput 10x without adding hardware.Cloudflare Security Insights system now processes over 120 scans per second, providing frequent insights for all customers. By optimizing Kafka consumers, Postgres queries, and our API, we scaled our throughput 10x without adding hardware.扩展字段
{ "authors": [ "Dave Baxter" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2RqXjRJ4riFkCewNcsJ0T3/41f324b3debcc2956cd2d3bfc9aa6248/Scaling_Security_Insights-_how_we_achieved_a_10x_increase_in_global_scanning_capacity-OG.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/47SPUZ0TBAoySIlzGM9DSP/430fa22602f08d412aec8bbc29b39bb1/Dave_Baxter_.webp", "modified_time": "2026-06-12T13:41:48.030Z", "tags": [ "Application Security", "Security Posture Management", "Engineering", "Postgres", "Kafka" ] } -
Route public traffic to private applications with Cloudflare
Application Services for Private Origins is available now in closed beta. Route public hostnames to private IP origins over your existing IPsec, GRE, CNI, or Cloudflare Mesh paths. No public IPs or extra connector software required.
Application Services for Private Origins is available now in closed beta. Route public hostnames to private IP origins over your existing IPsec, GRE, CNI, or Cloudflare Mesh paths. No public IPs or extra connector software required.Application Services for Private Origins is available now in closed beta. Route public hostnames to private IP origins over your existing IPsec, GRE, CNI, or Cloudflare Mesh paths. No public IPs or extra connector software required.扩展字段
{ "authors": [ "Enrique Somoza", "Steve Welham", "Shruti Mittal" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6rWfW796xuEhQUTPCRjpRY/7e0cec73f9a729c80960eca420c45541/OG_Share_2024-2025-2026__37_.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/ZN26DuKKzZWE46aYueH7N/42ca46b984093f4ae576c421e9cb8e8f/82d2d6831ab9d835.webp", "modified_time": "2026-06-10T13:00:05.564Z", "tags": [ "Application Services", "Private Network", "DNS", "Pingora", "Cloudflare One", "Cloudflare Zero Trust", "Zero Trust", "Product News" ] } -
Defend against frontier cyber models: Cloudflare's architecture as customer zero
In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.
In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.扩展字段
{ "authors": [ "Rohit Chenna Reddy", "Chase Catelli", "Dan Jones" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7IDIlD55jcZH6evYpTDert/9c6865086c66d5947ee83c5d1a330ac8/OG_Share_2024-2025-2026__38_.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2dda3QlEIYII5ugcPrsqmd/35d4f9bd6c5cc349bd34e10cf5340d78/fad46a42388a0bc6.webp", "modified_time": "2026-06-10T17:23:22.530Z", "tags": [ "Security", "AI", "Threat Intelligence", "Risk Management", "Customer Zero", "WAF", "Zero Trust", "Cloudforce One", "Bot Management" ] } -
Turning Cloudflareâs threat indicators into real-time WAF rules
Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.
Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.扩展字段
{ "authors": [ "Alexandra Moraru", "Harsh Saxena", "Georgie Yoxall", "Brian Seel" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/32I6Ez9J5ahGTUfRFr0vGe/982fdf4be26c2c7c11e04507a8e43c0d/Turning_Cloudflare%C3%A2__s_threat_indicators_into_real-time_WAF_rules-OG.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/URwbDrA0k9GNtNsCsAC7N/930223a35d0c7a39cb843e44f530ccba/alexandra.png", "modified_time": "2026-06-08T15:16:52.695Z", "tags": [ "Security", "WAF", "Threat Intelligence", "Cloudforce One", "Product News" ] } -
Your AI bill is out of control. Cloudflare can fix it now.
AI Gateway now features real-time spend limits to prevent runaway token bills across multiple AI providers. By integrating with Cloudflare Access, companies can use identity-driven budgets and policies.
AI Gateway now features real-time spend limits to prevent runaway token bills across multiple AI providers. By integrating with Cloudflare Access, companies can use identity-driven budgets and policies.AI Gateway now features real-time spend limits to prevent runaway token bills across multiple AI providers. By integrating with Cloudflare Access, companies can use identity-driven budgets and policies.扩展字段
{ "authors": [ "Ming Lu", "Kenny Johnson" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/10aPjUkoN4qtMrhmFvJXjU/39e514a0d40f1059d73c342e15c4ab5a/Your_AI_bill_is_out_of_control._Cloudflare_can_fix_it_now._-OG.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/15tKckibXhwPEckLeCWGle/a0bc2f5d0219244489150cc090c04357/0b44a65c-00b0-4550-8cbd-724f7960252a_800x800.png", "modified_time": "2026-06-05T13:41:25.394Z", "tags": [ "AI", "AI Gateway", "Cloudflare Access", "Developers", "Developer Platform" ] } -
VoidZero is joining Cloudflare
VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone.
VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone.VoidZero, the team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare. Vite stays open source, vendor-agnostic, and built for everyone.扩展字段
{ "authors": [ "Evan You", "Steve Faulkner" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/77PFBBDzFzIVtsPi4GXm5g/ea71873167012a47518dc593033032c6/BLOG-VOID_OG.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5q0ygYBDtJWpcpXGq44J1c/69dae4b569364049995d712d2418a5f8/tqUTHDB0.jpg", "modified_time": "2026-06-09T11:55:27.704Z", "tags": [ "Acquisitions", "Developers", "Developer Platform", "AI", "Workers AI", "Vite" ] } -
Enforcing the First AS in BGP AS PATHs
BGP is vulnerable to routing hijacks and path leaks that negatively impact traffic on the Internet. RPKI helps solve some of these problems, but for some forged paths, we need to rely on a simpler mechanism: First AS enforcement in BGP.
BGP is vulnerable to routing hijacks and path leaks that negatively impact traffic on the Internet. RPKI helps solve some of these problems, but for some forged paths, we need to rely on a simpler mechanism: First AS enforcement in BGP.BGP is vulnerable to routing hijacks and path leaks that negatively impact traffic on the Internet. RPKI helps solve some of these problems, but for some forged paths, we need to rely on a simpler mechanism: First AS enforcement in BGP.扩展字段
{ "authors": [ "Bryton Herdes", "Bryce Walters", "Mingwei Zhang" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3Tz1vzJHg2Jc7ao1HVBTHE/8d572762f11b749dc47694f482063413/Enforcing_the_First_AS_in_BGP_AS_PATHs-OG.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2CtRZInMXDzWbBSlJZq6ob/0129b54a75408333b82b7ab77991bfb4/Bryton_Herdes_.jpeg", "modified_time": "2026-06-08T10:01:36.772Z", "tags": [ "BGP", "Routing", "Routing Security", "RPKI", "Radar" ] } -
How we reduced core unit boot time from hours to minutes
We investigated why firmware updates were causing our core servers to take four hours to reboot. By diving into UEFI data structures and iPXE automation, we eliminated unnecessary timeouts and cut boot times back down to minutes.
We investigated why firmware updates were causing our core servers to take four hours to reboot. By diving into UEFI data structures and iPXE automation, we eliminated unnecessary timeouts and cut boot times back down to minutes.We investigated why firmware updates were causing our core servers to take four hours to reboot. By diving into UEFI data structures and iPXE automation, we eliminated unnecessary timeouts and cut boot times back down to minutes.扩展字段
{ "authors": [ "Giovanni Pereira Zantedeschi", "Nnamdi Ajah", "Omar Sheikh-Omar" ], "hero_image": "https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2sNWgFFJRChSJRDf86w7Sk/17c01739d21d896363b098a4c0c47967/BLOG-3108_OG.png", "listing_image": "https://blog.cloudflare.com/cdn-cgi/image/format=auto,dpr=3,width=64,height=64,gravity=face,fit=crop,zoom=0.5/https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7A7A57tAXHrOynxnx3eFpi/15cfa82b216391c547be01178e30cd98/giovanni.jpg", "modified_time": "2026-06-08T21:12:46.508Z", "tags": [ "Infrastructure", "Engineering", "Networking", "Core" ] }