Home / Companies / Cloudflare / Blog / December 2021

December 2021 Summaries

53 posts from Cloudflare

Filter
Month: Year:
Post Summaries Back to Blog
As we approach the end of 2021, it's time to reflect on the past year and make predictions about what lies ahead in 2022. One major trend that will continue to grow is the adoption of 5G networks, which offer vastly more wireless bandwidth and lower network latency. This technology will improve the performance of websites, business applications, video streaming, online games, and emerging technologies like AR/VR. The shift towards remote work will also drive increased adoption of 5G mobile and fixed wireless broadband. Another significant trend is the "great reshuffle" in the tech industry, as workers seek new opportunities and companies compete to attract the best talent. Employers must make working remotely easy and secure to stay competitive in this job market. Technology and tools will increasingly tip the balance in the talent war, with companies looking for every technological advantage to attract the talent they need. Companies will also continue to adopt cloud services as a way to simplify their business processes and automate tasks. IT leaders will expect cloud services to simplify instead of adding more complexity, and will demand more value from their cloud partners to keep costs under control. Security is another area that will see increased focus in 2022, with companies embracing zero trust security models to protect against the growing threat landscape. The security-as-a-service model will tend to win for the same reasons as cloud adoption – simplicity and minimal headcount requirements. The corporate network (WAN) is becoming increasingly obsolete, as work-from-home arrangements make it an anachronism. Video conferencing and SaaS apps now run better at home than at the office for many of us, and the broader rollout of 5G will make things even better for mobile users. Finally, data privacy for businesses is critical to get right due to the scope of the privacy issues at hand. Companies must architect applications with privacy laws in mind from the outset, and consider how they can navigate the patchwork of global regulations around data privacy. Browser isolation and the evolution of zero trust security controls will help companies achieve end-user device independence while maintaining privacy and security standards.
Dec 31, 2021 1,620 words in the original blog post.
The COVID pandemic continued to impact Internet traffic in 2021, with global internet traffic growing throughout the year and reaching its peak in December. Lockdowns or restrictions affected where and how people went online, leading to fluctuations in internet usage across different countries. In the United States, mobile traffic took the lead for the first time during Thanksgiving week. Cyberattacks were also prevalent, with July and November being the months with the highest peak of attacks. E-commerce traffic peaked on Black Friday in various cities, while messaging traffic saw a surge on New Year's Day in New York City.
Dec 23, 2021 2,900 words in the original blog post.
In 2021, TikTok surpassed Google to become the most popular domain globally according to Cloudflare Radar data. Other top domains included Facebook, Microsoft, Apple, Amazon, Netflix, YouTube, Twitter, and WhatsApp. Social media platforms such as TikTok, Facebook, YouTube, Twitter, Instagram, Snapchat, Reddit, Pinterest, LinkedIn, and Quora were all in the top 100 list of most popular global domains. In terms of video streaming, Netflix continued to dominate with Amazon Prime not included due to its use of Amazon.com as a domain. E-commerce domains such as Amazon, Taobao, eBay, Walmart, Jd.com, Shopify, Bestbuy, Target, Rakuten, and Homedepot were also popular throughout the year. Space travel achievements by NASA, SpaceX, Blue Origin, and Virgin Galactic led to increased traffic for their respective domains. WhatsApp remained the most popular chat domain, followed by Telegram, WeChat, and Signal. Roblox surpassed Fortnite as the most popular metaverse domain in 2021.
Dec 20, 2021 3,439 words in the original blog post.
Cloudflare has announced support for Remix applications on its full-stack platform, Cloudflare Pages. Remix is a new framework focused on fully utilizing web capabilities and emphasizing web fundamentals such as HTTP status codes, caching, and performance optimization. The integration with Cloudflare Workers allows developers to reuse knowledge gained from building apps in the browser while offering better performance due to native compatibility and proximity to users. Remix already tightly integrates with KV for session storage, and a Durable Objects integration is in progress. Deploying Remix applications on Cloudflare Pages involves running npx create-remix@latest, creating a repository on GitHub or GitLab, pushing the code, and selecting "Remix" from the framework presets dropdown.
Dec 17, 2021 761 words in the original blog post.
In July 2021, Cloudflare announced its intention to launch Crawler Hints as a means to reduce the environmental impact of web searches by helping search indexers make more informed decisions on when content has changed. The first iteration of Crawler Hints was made available in October 2021. By leveraging data from Cloudflare's global network, Crawler Hints generates a "content freshness score" to inform crawlers of content changes and improve efficiency for both customers and search engines. Since its launch on October 18, 2021, Crawler Hints has processed over twenty-five billion crawl signals and been opted in by more than 81,000 customers.
Dec 16, 2021 2,401 words in the original blog post.
A recent bug bounty report revealed that a private key used for pkg.cloudflareclient.com was exposed. The company has since rotated the key and is taking steps to prevent similar issues in the future. This incident highlights the importance of proper security measures when using third-party repositories, as an improperly secured private key can have consequences beyond one repository. To improve the security of apt with third-party repositories, users should ensure that keys are only trusted for specific sources and use https to further secure their packages.
Dec 15, 2021 1,199 words in the original blog post.
A second Log4J vulnerability, CVE-2021-45046, has been identified following the initial CVE-2021-44228. This new vulnerability is actively being exploited and users should update to version 2.16.0 as soon as possible. Cloudflare WAF customers have three rules available for mitigating exploit attempts, with an additional fourth rule providing broader protection but at the cost of a higher false positive rate. Log4J is a Java-based logging library maintained by Apache Software Foundation and is affected in all versions >= 2.0-beta9 and <= 2.14.1 due to JNDI features that can be exploited for remote code execution.
Dec 15, 2021 295 words in the original blog post.
The blog post discusses evasion patterns and exfiltration attempts related to the CVE-2021-44228 vulnerability, also known as Log4Shell. It highlights that attackers initially used simple strings for exploitation but quickly switched to more complex methods to bypass Web Application Firewalls (WAFs). The post provides examples of evasion techniques and explains how the language used in Log4j allows for obscuring key strings. Additionally, it presents a chart showing the evolution of blocked attacks over time. The article emphasizes the importance of patching systems with up-to-date Log4j or applying mitigations to prevent exploitation.
Dec 14, 2021 1,221 words in the original blog post.
On December 9, 2021, a zero-day exploit called CVE-2021-44228 was discovered affecting Apache Log4j utility. Cloudflare has updated its WAF to protect against this vulnerability and advises customers to update their systems promptly. The company is also mitigating any exploits attempted via Cloudflare Logs, which are seeing the exploit pattern in logs sent to customers up to 1000 times every second. Customers can now update their Logpush jobs to automatically redact tokens that could trigger this vulnerability by setting CVE-2021-44228=true in their Logpush job options configuration. This redaction replaces the token ${ with x{ in logs, and is not currently available in the Cloudflare Dashboard but can be modified using the API.
Dec 14, 2021 417 words in the original blog post.
Cloudflare has introduced a new product called "Bulk Redirects" that allows administrators to upload and enable hundreds of thousands of URL redirects within minutes, without having to write any code. This feature is designed to simplify the management and implementation of URL redirects at scale for customers with large numbers of zones and customers under management. The packaging model for Bulk Redirects closely resembles that of "IP Lists", allowing accounts to be entitled to a set number of Edge Rules, Bulk Redirect Lists, and URL Redirects depending on the highest Cloudflare plan within their account.
Dec 13, 2021 3,368 words in the original blog post.
The text discusses how Cloudflare is addressing connectivity challenges faced by IT teams and CIOs. It presents three parts of their approach: making the network more valuable, expanding reach, and reducing provisioning times. They aim to make interconnection valuable by providing access to new products and features with zero additional latency and easy configuration. The network becomes more useful as more properties connect to it, improving performance and threat detection. Cloudflare offers various interconnection options in over 250 locations worldwide, including through Interconnect Partners. They are expanding their reach to 1000 new locations as part of Cloudflare for Offices initiative. To get interconnection done quickly, they are automating BGP configurations, streamlining cross-connect provisioning, and improving uptime. The text also mentions partnerships with companies like Megaport and Console Connect to provide virtual interconnection.
Dec 11, 2021 1,965 words in the original blog post.
Cloudflare has expanded its security offerings and obtained new compliance certifications, including being listed on the FedRAMP Marketplace as 'In Process' for receiving an agency authorization at a moderate baseline. The company is also one of the first in the industry to achieve ISO 27701 certification as both a data processor and controller. Additionally, Cloudflare has met the requirements of SOC-2 Type II / SOC 3, ISO 27001:2013, PCI Data Security Standard (DSS), and HIPAA/HITECH Act. The company is currently evaluating ISO 27018 for handling personal data in its cloud platform and will continue to pursue validations that support customer needs and make the internet safer and more secure.
Dec 11, 2021 787 words in the original blog post.
Cloudflare has introduced HTTP Applications and Routing Rules as part of its closed beta program. This new feature allows users to safely test and deploy changes to their HTTP traffic by versioning configuration settings and controlling when these changes roll out on the company's global edge network. Enterprise customers seeking greater control can reach out to their Customer Success Manager for access. The previous method of managing configurations through Zones posed challenges, including manual setup requirements for staging environments and risks of drift in configuration between production and staging settings. HTTP Applications enable users to manage edge configuration by use case rather than hostname, with each application consisting of versions of configurations that are independent but can be controlled using Routing Rules.
Dec 11, 2021 1,747 words in the original blog post.
In this blog post from December 11th, 2021, Natasha Wissman discusses recent updates to Cloudflare's Notification center. The company recognizes the importance of notifications for its customers and has introduced new types of notifications over time. One significant change is the shift from emails to webhooks as a notification delivery method. Webhooks are more versatile, allowing integration with various messaging platforms and services such as Slack, Microsoft Teams, Google Chat, DataDog, Discord, OpsGenie, and Splunk. Additionally, Cloudflare has introduced "notification history," which allows users to view a log of sent notifications for the past 30 or 90 days depending on their plan. This feature helps prevent loss of important information and is currently available via API with plans for future integration into the Cloudflare Dashboard.
Dec 11, 2021 713 words in the original blog post.
CIO week featured new product innovations aimed at improving security and usability of Cloudflare's platform. Updates included streamlined Single Sign-On (SSO) onboarding, beta program for zone scoped roles, Terraform improvements with 10 new resources added in 2021, enhanced notifications and alerts, data protection and locality enhancements, expanded logging capabilities, and integration of R2 as a log storage destination. These updates reflect Cloudflare's commitment to meeting the evolving security needs and depth of control that customers require.
Dec 11, 2021 1,039 words in the original blog post.
Cloudflare, a company focused on enhancing internet security and reliability, has announced new integrations with mobile device management (MDM) vendors to simplify the deployment of its Cloudflare WARP agent. The integration aims to provide a streamlined process for administrators to enroll entire fleets of devices in the service. MDM solutions are designed to manage all an organization's devices from a single platform, addressing challenges posed by distributed working environments and enabling IT teams to configure policies, update operating systems, and install new software remotely. Cloudflare's device client, WARP, helps organizations enhance security and visibility across their dispersed users by enabling identity and device posture-aware policy enforcement at the endpoint. The company has optimized its client for diverse deployment approaches and is partnering with leading MDM vendors to ensure compatibility and provide purpose-built documentation for protecting users.
Dec 10, 2021 1,084 words in the original blog post.
On December 10th, a vulnerability in the Java-based logging package, log4j, was disclosed, allowing attackers to execute code on remote servers. Cloudflare has updated its WAF to defend against this 0-day attack and recommends patching instances of log4j immediately. The attack exploits servers with unrestricted connectivity to the public Internet. To address this issue, deploying Cloudflare One can filter and log how infrastructure connects to any destination. Additionally, securing traffic inbound and outbound, protecting against malicious DNS queries, and inspecting and filtering HTTP traffic are crucial steps for network security.
Dec 10, 2021 1,077 words in the original blog post.
On December 9, 2021, a severe vulnerability in the Java-based logging package Log4j was disclosed. This flaw allows an attacker to execute code on a remote server, known as Remote Code Execution (RCE). The vulnerability, CVE-2021-44228, affects version 2 of Log4j between versions 2.0-beta-9 and 2.14.1, and is patched in 2.16.0. This issue has been deemed one of the most serious vulnerabilities on the internet since Heartbleed and ShellShock due to the widespread use of Java and Log4j. Cloudflare has implemented firewall rules to protect its clients from this vulnerability, while also ensuring that their systems are not vulnerable or have mitigated the issue. Companies using Java-based software with Log4j should immediately apply mitigation techniques to protect their systems.
Dec 10, 2021 1,123 words in the original blog post.
Cloudflare has observed a continuous increase in scanning and attempted exploitation of the CVE-2021-44228 vulnerability in Log4j since its discovery. The largest number of scans or exploitation attempts have come from Canada and then the United States. Most of the blocked requests appear to be reconnaissance to determine if a server is vulnerable. Cloudflare's security teams are working continuously to update WAF and firewall rules as needed in response to evolving exploit attempts.
Dec 10, 2021 599 words in the original blog post.
On December 9, 2021, a zero-day exploit (CVE-2021-44228) affecting the Apache Log4j utility was made public, leading to remote code execution. The vulnerability is actively being exploited and users of Log4j are advised to update to version 2.15.0 as soon as possible. Alternatively, the issue can be mitigated by removing the JndiLookup class from the class path or setting specific system properties/environment variables. Cloudflare WAF customers can leverage three newly deployed rules to help mitigate exploit attempts. The situation is being monitored and managed rules will be updated accordingly. Log4j, a Java-based logging library maintained by Apache Software Foundation, is affected in all versions >= 2.0-beta9 and <= 2.14.1.
Dec 10, 2021 288 words in the original blog post.
Cloudflare has joined the Microsoft 365 Networking Partner Program (NPP), which aims to provide customers with a set of partners whose deployment practices align with Microsoft's networking principles for Microsoft 365, ensuring optimal connectivity and user experience. Through Cloudflare One, organizations can now ensure as direct a connection as possible for Microsoft 365 traffic, benefiting from seamless user experiences while maintaining security through Cloudflare's global network and security suite of products.
Dec 10, 2021 1,034 words in the original blog post.
Cloudflare has announced the general availability of Argo for Packets, which optimizes IP layer network performance by finding the fastest path for traffic on the Internet. This feature is now available for products like Magic Transit, Magic WAN, and Cloudflare for Offices. Argo for Packets provides an average 10% latency improvement across the world in internal testing, with real-world numbers matching this figure. The technology improves customer performance by leveraging Cloudflare's existing global network and backbone, along with networking data from traffic already being sent over to optimize routes back to customers.
Dec 10, 2021 1,641 words in the original blog post.
Companies face significant risks online, with one of the greatest being the compromise of a domain name. To address this issue, Cloudflare has introduced Cloudflare Domain Protection for all its Enterprise customers at no additional cost. This new level of protection includes three layers of security to prevent unauthorized transfers, name server updates, and suspensions or deletions. The solution is designed to be scalable and secure, ensuring that mission-critical domains are protected from potential threats.
Dec 10, 2021 1,578 words in the original blog post.
On December 9, 2021, a serious vulnerability in the popular Java-based logging package Log4j was publicly disclosed. Cloudflare's security teams quickly responded by addressing two distinct questions: ensuring customer infrastructure protection and securing their own environment. The vulnerability allows an attacker to execute code on a remote server, making it one of the most serious vulnerabilities since Heartbleed and ShellShock. Upgrading to Log4j version 2.15 is recommended as a mitigation strategy. Cloudflare's response involved creating a timeline of events, addressing internal impact by identifying all software running on the JVM, reviewing external reports, and validating whether any assets were compromised through network analytics and endpoint analysis. They found no evidence of compromise and confirmed that their defense-in-depth approach worked effectively.
Dec 10, 2021 1,801 words in the original blog post.
Cloudflare has announced feature parity for its zero trust agent across all major platforms, including Windows 8.1, Windows 10 and Windows 11, macOS Mojave, Catalina, Big Sur, Monterey, ChromeBooks manufactured after 2019, Linux CentOS 8, RHEL, Ubuntu, Debian, iOS, and Android. The zero trust agent now supports new options to determine how traffic is routed and allows administrators to orchestrate deployment at scale. Additionally, the company has built the Cloudflare for Teams agent to be seamless to deploy at scale in an organization, with API and Terraform-based controls available.
Dec 10, 2021 1,496 words in the original blog post.
The blog discusses the evolution of email security and introduces the concept of "Integrated Cloud Email Security" (ICES) solutions as a new category in Gartner's 2021 Market Guide for Email Security. With cloud messaging becoming the standard, traditional Secure Email Gateways are being replaced by cloud-native email protection options. ICES offers advanced threat detection, ease of use, and improved visibility and response compared to traditional SEGs. Area 1 Security is recognized as a Representative Vendor in this growing new category. The blog also highlights the challenges faced by traditional email security systems and predicts that nearly half of all organizations will switch to using built-in protection capabilities from cloud email providers and ICES rather than a SEG by 2023.
Dec 09, 2021 1,154 words in the original blog post.
The usage of SaaS applications has significantly increased over the past decade, reaching $145 billion in global spending in 2021 and projected to reach $171 billion in 2022. However, this growth presents challenges for CIOs and security teams due to the lack of required security controls or visibility in many SaaS applications. The rise of remote work has made it difficult for IT teams to monitor application usage, leading to an increase in "shadow IT" – unapproved applications used by employees without IT knowledge. Cloudflare for Teams has updated its Zero Trust platform to address these challenges, providing a framework to identify new applications, block them, and provide access to approved ones. The platform also offers features such as blocking the right applications with meaningful error messages, protecting approved applications through secure authorization and audit trails, and making it easy for users to access all their approved applications in one place.
Dec 09, 2021 782 words in the original blog post.
Cloudflare has announced a cyber risk partnership program with leading cyber insurance carriers and incident response providers to help customers reduce their cyber risk. The company's objective is to provide enhanced coverage and discounted premiums for customers using its security suite, which offers comprehensive protection against common threat vectors. Insurance partners include At-Bay, Coalition, and Cowbell Cyber, while incident response partners are CrowdStrike, Mandiant, and Secureworks. The partnership aims to incentivize businesses to adopt stronger security controls and reduce their cyber risk.
Dec 09, 2021 1,708 words in the original blog post.
Cloudflare has announced updates to its Magic Firewall, adding security and visibility features that are crucial for modern cloud firewalls. The enhancements include threat intel integration and geo-blocking for improved security, as well as packet captures at the edge for better visibility. Magic Firewall is a network-level firewall delivered through Cloudflare to secure enterprises' remote users, branch offices, data centers, and cloud infrastructure. It integrates deeply with Cloudflare, providing a comprehensive overview of all network activities. The new features aim to provide additional layers of security and visibility without requiring decryption at the Application Layer.
Dec 09, 2021 1,148 words in the original blog post.
Cloudflare has extended its DDoS protection control for customers using Magic Transit and Spectrum services. Enterprise customers can now tune and tweak their L3/4 DDoS protection settings directly from the Cloudflare dashboard or via the API. The new functionality provides control over two main DDoS rulesets: Network-layer DDoS Protection ruleset, which includes rules to detect and mitigate attacks on layer 3/4 of the OSI model; and Advanced TCP Protection ruleset, which includes rules for sophisticated out-of-state TCP attacks.
Dec 09, 2021 1,570 words in the original blog post.
Today, Cloudflare launched its Security Center, a unified security intelligence solution that combines the company's suite of security products, expertise, and unique Internet intelligence. The new platform aims to help customers understand their attack surface and quickly take action to reduce their risk of an incident. With features like Security Insights and Infrastructure, users can review potential security risks and vulnerabilities associated with their IT infrastructure, as well as manage their IT assets on Cloudflare. The beta release is included in existing Cloudflare plans, and the company plans to continue adding more features to the Security Center in the future.
Dec 09, 2021 1,261 words in the original blog post.
Cloudflare has acquired Zaraz and launched a beta version of Cloudflare Zaraz, which integrates Zaraz's product into Cloudflare's systems and dashboard. This new tool allows users to manage and load third-party tools on the cloud, improving speed, privacy, and security. The acquisition aims to solve problems caused by traditional Tag Managers and Customer Data Platforms, such as third-party bloat and security risks. Zaraz can significantly boost a website's performance by optimizing how it loads third-party tools, running scripts on the cloud backend instead of in the browser. This also creates an extra layer of security and control over sensitive information passed to third-party vendors. Instacart has successfully used Zaraz to improve page speed and increase security and privacy. Cloudflare plans to expand Zaraz's feature set, collaborate with SaaS companies and vendors, and make it possible for everyone to build better, faster, and more secure products easily.
Dec 08, 2021 2,430 words in the original blog post.
In a recent announcement, Cloudflare revealed that it will soon extend identity-driven access controls on its network to include session and login interval control for private networks. This development aims to address the limitations of traditional private networks in adapting to increasingly remote work environments. By leveraging Cloudflare's global network, users can securely connect their private networks to the platform using outbound-only tunnels or more conventional connection approaches like GRE or IPSec tunnels. This enables administrators to create granular, identity-based policies for controlling user access to specific applications on certain IP addresses or hostnames. The upcoming beta release will also introduce support for UDP and allow users to map their application hostnames on local domains, preventing issues with clashing or ephemeral private IP addresses.
Dec 08, 2021 890 words in the original blog post.
Kudelski Security has developed an in-house solution using Cloudflare's Identity-aware Proxy (IAP) to automate secure access for developers to different Kubernetes (K8s) control-plane APIs across multiple cloud environments. The automation tool, called 'k8s-tunnels', saves time and enhances security by enabling developers to surface all the K8s services they have access to in a given cloud environment, authenticate an access request using Cloudflare's Zero Trust rules, and establish a connection to that cluster via Cloudflare's IAP. This approach helps maintain small, micro-segmented environments and supports a Zero Trust security model.
Dec 08, 2021 1,684 words in the original blog post.
Cloudflare has launched early access to UDP on its Zero Trust platform, allowing organizations to build private networks without relying on traditional VPNs. The platform uses Cloudflare Tunnel on the server side and Cloudflare WARP on the client side, eliminating the need for legacy hardware such as VPN concentrators, internal firewalls, and load balancers. With UDP support, users can now access applications that depend on near real-time communication like video streaming or VoIP services. Additionally, organizations can use Cloudflare's developer documentation to get started with building their private networks.
Dec 08, 2021 1,667 words in the original blog post.
Cloudflare has announced Foundation DNS, a new premium DNS offering designed for enterprise customers. The service is based on a single input for pricing - total DNS queries per month - and includes unlimited DDoS mitigation without hidden overage fees. Foundation DNS aims to provide unparalleled reliability and performance while meeting the complex requirements of infrastructure teams. In addition, Cloudflare has introduced support for outgoing zone transfers for Secondary DNS and Logpush for authoritative and secondary DNS queries as part of this new offering. The company is also working on Multi-Signer DNSSEC and joining the DNS Operations, Analysis, and Research Center (DNS-OARC) to tackle challenges in the DNS ecosystem.
Dec 08, 2021 2,867 words in the original blog post.
Zaraz is a platform that aims to improve website performance by moving third-party code execution from browsers to edge servers. This reduces the load on browsers and enhances security as it prevents untrusted or unknown origin scripts from running in the browser. The platform also offers an event system for triggering tool executions at specific times with relevant data, improving user experience and website interactivity. Zaraz is compatible with popular third-party tools and supports custom tool creation by vendors. It integrates seamlessly with Cloudflare's infrastructure, offering additional benefits such as inlining code and eliminating DNS resolution time for scripts. The platform is currently available in beta version and has an enterprise waitlist.
Dec 08, 2021 3,477 words in the original blog post.
Supply chain attacks are becoming increasingly concerning for CIOs and security professionals. During these attacks, an attacker compromises a third-party tool or library used by the target application, potentially leading to data theft or further attacks. To help identify and mitigate such threats in web applications, Cloudflare has launched Page Shield in General Availability (GA). This solution provides visibility into scripts running on an application and notifies users when compromised or malicious behavior is detected. Page Shield leverages its position as a reverse proxy to receive information directly from the browser about loaded JavaScript files and modules. It then analyzes this data and warns users of any malicious behavior, such as attempts to exfiltrate user data. Examples of compromised scripts include Magecart attacks, cryptomining, and adware. Cloudflare's Enterprise customers can purchase the full set of Page Shield capabilities, including detection and prevention options.
Dec 08, 2021 1,287 words in the original blog post.
Cloudflare has announced the beta release of its clientless web isolation feature, a new on-ramp for Browser Isolation that integrates Zero Trust Network Access (ZTNA) with the benefits of remote browsing. This solution allows users to browse websites, internal apps or SaaS applications securely without needing to install any software or configure certificates on their devices. The clientless web isolation streamlines connections to remote browsers through a hyperlink and can be initiated through a prefixed URL. It also integrates with Cloudflare's Zero Trust platform for secure internet access, application access, and data protection controls. This feature is available as a capability to Cloudflare for Teams subscribers who have added Browser Isolation to their plan.
Dec 08, 2021 806 words in the original blog post.
Cloudflare has acquired Zaraz, a company that aligns with its mission to make the web more secure, reliable, and faster. The acquisition comes as a response to the growing risk posed by third-party scripts embedded on websites. These scripts can cause slow rendering pages or even steal data if they are compromised. Zaraz offers a solution that allows strict control over what these scripts do, ensuring that CIOs and CISOs can sleep well at night knowing their web presence is secure. Cloudflare has made Zaraz available to its Enterprise customers immediately, with other customers able to access a free beta version on their dashboard starting today.
Dec 08, 2021 1,393 words in the original blog post.
Cloudflare has acquired Zaraz and launched a beta version of Cloudflare Zaraz, which allows users to manage and load third-party tools on the cloud for significant speed, privacy, and security improvements. The platform aims to replace traditional Tag Managers and Customer Data Platforms by optimizing how websites load third-party tools, reducing bloat, and enhancing performance. Instacart has already reported substantial improvements in page speed and security after using Zaraz. As part of Cloudflare, Zaraz will evolve into a platform for building server-side integrations on the edge, with features such as geolocation triggers and Data Loss Prevention.
Dec 08, 2021 2,439 words in the original blog post.
Data localization has become a significant concern in recent years as various countries seek to control or protect their citizens' data. Countries such as Australia, China, India, Brazil, and South Korea have implemented or are considering regulations that assert legal sovereignty over personal data of their citizens. The EU's General Data Protection Regulation (GDPR) is one of the world's most comprehensive data privacy laws, but it does not mandate that personal data must stay within Europe. In response to these concerns and developments, Cloudflare has introduced the Data Localisation Suite, which provides customers with control over where their data is inspected and stored. The suite includes the Customer Metadata Boundary, which ensures that a customer's end-user traffic metadata stays in the EU. This helps address the third concern of many customers who want to keep metadata local as well. The Data Localisation Suite is focused on helping customers in the EU localize data for their inbound HTTP traffic and includes products like Cache, Firewall, DDoS protection, and Bot Management. Cloudflare plans to expand this suite globally and include more of its Data Localisation Products, such as Geo Key Manager and Regional Services. Additionally, they are working on expanding the Metadata Boundary to include their Zero Trust products like Cloudflare for Teams.
Dec 07, 2021 1,148 words in the original blog post.
Cloudflare is introducing a new feature that allows customers to store their logs on Cloudflare R2 storage, providing consolidation opportunities for CIOs and Security Teams. This move aims to simplify infrastructure, save costs, and enhance security. The integration of log storage with R2 addresses the gaps in existing logging solutions by offering a cost-effective way to store logs for any period of time across all Cloudflare products. By storing logs on Cloudflare, customers can gain insights into their network traffic and troubleshoot issues more effectively. This feature is part of Cloudflare's ongoing efforts to improve its logging capabilities and provide comprehensive data analysis tools for its users.
Dec 07, 2021 897 words in the original blog post.
Cloudflare has introduced a new Browser Isolation service to protect against phishing attacks and credential theft within web browsers. Administrators can define Zero Trust policies, such as prohibiting keyboard input and file uploads during high-risk browsing activities. The service is integrated natively into Cloudflare's Secure Web Gateway and Zero Trust Network Access services, allowing users to browse more of the internet without taking on risks. This solution helps administrators balance security needs with employee productivity by providing control over user interactions with risky websites.
Dec 07, 2021 794 words in the original blog post.
Cloudflare has announced new capabilities for its cloud-native firewall, designed to help customers transition from traditional hardware firewall appliances. The platform, called Cloudflare One, offers a secure and Zero Trust-enabled solution for administrators to apply consistent security policies across all users and resources. Built on top of Cloudflare's global network, the firewall eliminates the need for scaling, deploying, or maintaining edge security hardware. As part of this announcement, Cloudflare has launched the Oahu program to assist customers in leaving behind legacy hardware. The new capabilities address the problems faced by previous generations of firewalls and save IT teams time and money.
Dec 06, 2021 2,345 words in the original blog post.
Cloudflare One is a product suite designed to help enterprises build modern enterprise networks and operate efficiently and securely without on-premise hardware. It provides connectivity, security, and analytics tools from one vendor and control plane. Since its launch over a year ago, customers have used it at scale to solve various problems. The platform offers comprehensive network protection, including IP-layer DDoS mitigation and blocking threats with remote browser isolation. Additionally, Cloudflare One provides Zero Trust controls for accessing internal resources and SaaS applications. It also ensures fast and reliable performance while complying with local laws and regulations.
Dec 06, 2021 2,999 words in the original blog post.
Cloudflare has introduced new privacy features for administrators using its Gateway service, a Secure Web Gateway with built-in Zero Trust browsing controls. The latest updates include role-based dashboard access and selective logging of events, allowing administrators to control how user data is collected and who can audit those records. These enhancements provide more options for deciding the type of information logged by Cloudflare Gateway and enable organizations to build least-privilege controls into their deployment management.
Dec 06, 2021 913 words in the original blog post.
Cloudflare has announced support for IPsec as an on-ramp to its Cloudflare One network security suite. The company built this support due to customer demand for using IPsec at the network layer, owing to its universal vendor support and encryption across all traffic. This implementation is faster and easier to use than traditional IPsec connectivity and integrates deeply with the Cloudflare One suite to provide unified security, performance, and reliability across all traffic. The new system uses a global Anycast network, allowing customers to establish one IPsec tunnel to access 250+ locations. This is similar to the hub-and-spoke model but with a "hub" that is everywhere, fast, and easy to manage.
Dec 06, 2021 1,406 words in the original blog post.
Cloudflare's Magic Firewall is a distributed stateless packet firewall built on Linux nftables that runs on every server in their data centers worldwide. It provides advanced protection against sophisticated attacks by leveraging the Extended Berkeley Packet Filter (eBPF) technology to extend its use of nftables. The integration of eBPF allows for more powerful syntax and increased flexibility, enabling users to match on various packet parameters and implement advanced packet parsing and content matching. This makes Magic Firewall a highly effective solution for protecting networks from malicious traffic.
Dec 06, 2021 1,375 words in the original blog post.
As companies transition back to office work, IT teams face new challenges in managing hybrid working models and maintaining network security. Software-defined wide-area networking (SD-WAN) technology is being adopted by some organizations to address these issues. SD-WAN allows for the consolidation of management tasks and simplification of router configuration. Companies like Cloudflare are leveraging their global Anycast network as a new corporate backbone, enabling quick and easy connections between offices through SD-WAN. This approach provides performant and secure connectivity without the need for expensive dedicated lines or complex hardware setups. Additionally, using standard tunneling protocols allows for compatibility with various devices and routers, making it easier to manage and maintain network security across multiple platforms.
Dec 06, 2021 692 words in the original blog post.
The role of a Chief Information Officer (CIO) has evolved significantly due to changes in corporate networks over the past few years, leading to gaps in visibility and security, increased costs, and network fragility. However, CIOs can look forward to a brighter future with advancements in internet technology. Cloudflare is helping build an internet that's faster, more secure, reliable, private, and programmable, enabling organizations to build their next-generation networks on its platform. The company's vision for the corporate network of the future includes a shift towards using the Internet as the new corporate network, with features like Zero Trust security at Internet scale, better quality of experience everywhere in the world, and ease of use for meaningful change starting with just one flow.
Dec 05, 2021 3,353 words in the original blog post.
The Stopping Grinch Bots Act is a new legislation aimed at stopping holiday hoarders on the internet. The Grinch Bot is a program that makes automated requests to different websites, particularly during the holiday season when it attempts to purchase items before humans can complete their orders. It strikes first around Black Friday and Cyber Monday, leveraging its speed and efficiency to buy large quantities of exclusive items in seconds. Businesses are vulnerable to these attacks as nearly 44% of internet traffic comes from bad bots. Cloudflare has observed over 300 billion attempts by bots to "add to cart" during the year, with trillions more caught earlier in their efforts by Bot Management and security solutions. On Black Friday, Cloudflare blocked over 150 billion threats. To combat this issue, Cloudflare offers a free tool called Bot Fight Mode that stops bots and makes them pay through tarpit challenges and carbon offsetting tree planting.
Dec 03, 2021 1,007 words in the original blog post.
Cloudflare has introduced proactive alerts for Business and Enterprise customers, allowing them to set up notifications whenever a spike in firewall-related events is observed, indicating a likely ongoing attack. Alerts can be configured via email, PagerDuty or webhooks, providing flexible integrations across various systems. Two new notification types have been added: Security Events Alert and Advanced Security Events Alert. The system uses Z-score calculations to detect anomalies in Firewall events, with a z-score threshold of 3.5 initially configured. This is the first step towards building a comprehensive suite of notifications and incident management systems directly embedded in the Cloudflare dashboard.
Dec 03, 2021 722 words in the original blog post.