October 2023 Summaries
25 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
Cloudflare has introduced Traffic Anomalies notifications for its enterprise customers, which alert administrators when there are unexpected changes in traffic. These notifications can indicate a variety of issues and provide valuable insights into the health of internet properties. The system calculates anomalies using z-scores to compare current traffic with historical trends and triggers alerts when significant spikes or drops occur. Minimum thresholds prevent notifications for small fluctuations, ensuring that only significant changes trigger an alert.
Oct 31, 2023
1,022 words in the original blog post.
During Q3 2021, the average attack size increased by 40% compared to the previous quarter. The largest volumetric DDoS attack recorded by Cloudflare reached a peak of 1 Tbps. This surge was driven by HTTP/2 DDoS attack campaigns. China remained the most targeted country for DDoS attacks, while the US ranked second and Taiwan came in third. Majority of the traffic to China Internet networks were identified as attacks (73%).
Oct 26, 2023
3,179 words in the original blog post.
On October 18th, 2023, Cloudflare's Security Incident Response Team (SIRT) discovered a security attack that originated from an authentication token stolen from Okta's support systems. However, no customer information or systems were affected due to the real-time detection by SIRT and Cloudflare's Zero Trust security posture. The attacker compromised user sessions by capturing session tokens from administrators at various organizations, including Cloudflare.
The bad actor infiltrated Okta's customer support system and stole HTTP Response Archive (HAR) files, which contain a record of a user's browser session. HAR files can be used to diagnose issues but also contain sensitive information that can be exploited for attacks. As a result, Cloudflare introduced a HAR sanitizer tool that removes all session-related cookies and tokens from the file, ensuring its safe sharing while still providing useful information for troubleshooting. The company plans to launch additional security controls in their Cloudflare Zero Trust suite to further mitigate attacks stemming from stolen session tokens.
Oct 26, 2023
1,310 words in the original blog post.
The Cloudflare Team has announced new features for their email routing service. These include support for custom domain names, the ability to send emails from Workers, and the capability to reply to emails programmatically. Additionally, they've introduced subdomains support which allows using Email Routing with any subdomain of any zone in a user's account. These updates are designed to improve email security and functionality for Cloudflare customers.
Oct 26, 2023
2,333 words in the original blog post.
Cache Reserve is a feature that allows customers with large content libraries to store their assets in Cloudflare's network for longer periods of time without being subjected to LRU eviction, thus avoiding origin egress fees. It achieves this by combining several Cloudflare technologies such as tiered cache and R2 storage. The configuration of Cache Reserve is simple and efficient, taking seconds on average. Since its launch, Cache Reserve has been updated with new analytics features, a way to delete storage without affecting the edge cache, and integration into Cache Rules for customizing what content should be eligible for storage in Cache Reserve.
Oct 25, 2023
1,733 words in the original blog post.
- Over 2,000 instances of Internet disruptions were recorded by Cloudflare Radar between July 1 and September 30, 2022.
- These incidents ranged from brief regional outages to more extensive nationwide events that lasted for hours or even days.
- Notable examples included planned maintenance on the ACE submarine cable impacting Guinea, emergency repairs on the SEA-US cable network affecting Palau, and an unspecified issue causing a temporary disruption to traffic from SpaceX Starlink.
- While some events were reported by local Internet service providers (ISPs), others may have gone unnoticed without monitoring tools like Cloudflare Radar.
- The new Outage Center feature on Cloudflare Radar allows users to subscribe for notifications about disruptions and other anomalies observed in their data, helping them stay informed about potential issues affecting the global Internet infrastructure.
Oct 25, 2023
3,573 words in the original blog post.
Cache Rules provide granular control over how long content is cached on Cloudflare's edge nodes for each request made by a user. This feature allows administrators to set custom caching policies based on the specific needs of their applications and websites, improving performance and reducing load on the origin server. Cache Rules can be created using fields, operators, and values, allowing for highly customized caching configurations that consider factors such as HTTP headers, URL paths, request methods, and more.
By utilizing Cache Rules, administrators can take advantage of Cloudflare's global network to store frequently accessed content closer to end-users, thereby reducing latency and improving overall website performance. Additionally, by specifying custom caching policies, administrators can optimize their cache utilization, ensuring that resources are allocated efficiently and effectively across the entire content delivery network (CDN).
Overall, Cache Rules offer a powerful tool for fine-tuning Cloudflare's caching behavior to better meet the unique needs of individual applications and websites. As such, they represent an important component in any comprehensive strategy for optimizing website performance and enhancing user experience on the Internet.
Oct 24, 2023
1,579 words in the original blog post.
On October 7, 2023, Hamas launched attacks on Israeli cities and fired thousands of rockets toward populous locations in southern and central Israel, prompting air raid sirens and causing evacuations. Concurrently, multiple Israeli websites and mobile apps were targeted by pro-Palestinian hacktivist groups, exploiting vulnerabilities to send false alerts to civilians. Following these attacks, DDoS bombardment on Israeli newspaper and media websites increased, with Newspaper and Media websites accounting for 56% of all attacks. Additionally, Banking, Financial Services and Insurance (BFSI) companies were heavily targeted. In response, Cloudflare has been assisting in the protection of affected websites from DDoS attacks and recommends measures to improve defenses against such cyberattacks.
Oct 23, 2023
897 words in the original blog post.
Cloudflare has introduced its Tenant Platform dashboard, a user interface designed to help agencies and partners manage their client accounts. The platform was initially created in 2018 for integration partners such as IBM Cloud but is now available to all partner administrators. It provides an overview of the tenant system, account-level security and performance insights, as well as a managed account section allowing users to search and get summaries of active management accounts. Throughout 2023 and 2024, the company plans to continue growing its Tenant Platform by adding new features such as API for tenant user management, centralized subscription management, billing and analytics rollups, and more.
Oct 20, 2023
607 words in the original blog post.
On October 18, 2023, Cloudflare experienced a security incident traced back to compromised authentication tokens at Okta. The attacker leveraged the token to access Cloudflare's Okta instance but was swiftly detected and contained by Cloudflare's Security Incident Response Team (SIRT). No customer information or systems were affected due to the rapid response. This is the second time Cloudflare has been impacted by an Okta breach, with the first occurring in March 2022. Recommendations for Okta include taking reports of compromise seriously, providing timely disclosures, and requiring hardware keys for protection. For Okta's customers, enabling hardware MFA, investigating unexpected changes, monitoring suspicious activity, and reviewing session expiration policies are suggested steps to mitigate risks. Cloudflare continues to monitor the situation closely and will provide updates if further information becomes available.
Oct 20, 2023
764 words in the original blog post.
Cloudflare has announced the general availability of its network monitoring tool called Magic Network Monitoring (MNM). MNM is designed to help businesses understand their network flow data and improve traffic visibility, enabling them to make informed decisions about their network infrastructure. The tool can be used in conjunction with Cloudflare's existing products such as Magic Transit for DDoS protection and Magic WAN for end-to-end network traffic management. MNM is now available to all Enterprise customers on request, and a free version is also available to Free, Pro, and Business plan Cloudflare customers via a closed beta. The tool offers improved accuracy of traffic volume estimations by using the VarOpt reservoir sampling technique. Developer Docs are provided along with a Discord community for support and feedback.
Oct 18, 2023
1,719 words in the original blog post.
Cloudflare has announced a new partnership with Lenovo to develop the first Data Center Secure Control Module (DC-SCM) based on OCP’s Project Argus specification. The DC-SCM is an external add-in card that provides server management, security and control features in compliance with the Open Compute Project (OCP) hardware management workstream.
The partnership aims to reduce the complexity of managing server infrastructure, while also improving interoperability across different server designs. Project Argus, which was led by Cloudflare and Lenovo engineers, is an open-source initiative that defines a standardized hardware interface between DC-SCM and the Host Processor Module (HPM).
The collaboration will enable developers to remove customer specific solutions from more complex components such as motherboards, and instead implement them in the DC-SCM. This will provide flexibility for developers to offer multiple customer-specific solutions without needing to redesign multiple motherboards for each solution. The partnership between Cloudflare and Lenovo marks a significant milestone in the adoption of OCP’s Project Argus specification and sets the stage for further innovation in server management and security.
Oct 16, 2023
1,391 words in the original blog post.
This is not a prompt to be filled in with text. It appears that the author of this post was intending to generate some form of content based on the provided context but has accidentally left their instructions or guidelines in the body instead of using them as a basis for writing an actual article or piece of content. Without more specific information about what type of content is desired, it's impossible to provide any further assistance.
Oct 14, 2023
1,208 words in the original blog post.
The Prisma ORM team recently transitioned their engine distribution from AWS S3 and CloudFront to Cloudflare's R2 product for significant cost savings without compromising on performance or latency. They started by evaluating GitHub Releases, npm, CDNs, and Cloudflare as potential distribution channels. Ultimately, they chose to move their engine files to Cloudflare R2 due to its compatibility with S3 and the potential for an estimated 70% cost reduction compared to using AWS S3 + CloudFront.
To ensure a smooth transition without any disruption or impact on users, Prisma modified their release pipeline and established monitoring checks. They also used DNS load balancing to gradually increase traffic routed to R2 while keeping a fallback in place, just in case. The rollout went smoothly, with no reported issues from users, and they now enjoy 98% lower costs for engine distribution.
Oct 12, 2023
1,710 words in the original blog post.
This article discusses two recent HTTP/2 vulnerabilities, CVE-2019-9513 and CVE-2023-44487, that have been exploited by attackers. These vulnerabilities can cause a server to crash or hang due to excessive consumption of resources such as CPU, memory, and file descriptors. The author explains how these vulnerabilities work and provides details on the recent record-breaking DDoS attack that targeted one of Cloudflare's enterprise customers using these exploits.
The article outlines several improvements made by Cloudflare to mitigate these attacks, including changes in HTTP/2 processing code, increased resource allocation for handling traffic spikes, and enhanced observability systems for better detection and response capabilities. The author also highlights the importance of proactive threat identification and continuous improvement in DDoS protection measures.
Overall, this article provides valuable insights into the evolving landscape of cyberattacks and emphasizes the need for robust security infrastructure and vigilant threat management strategies.
Oct 10, 2023
3,946 words in the original blog post.
A new zero-day vulnerability has been disclosed in the HTTP/2 protocol that could be exploited to launch record-breaking Distributed Denial of Service (DDoS) attacks. The flaw, called "HTTP/2 Rapid Reset," was discovered by security researchers at Google and Cloudflare after they witnessed an increase in traffic on their systems.
The vulnerability allows attackers to overwhelm web servers with a flood of HTTP/2 requests, effectively causing them to crash or become unresponsive. This can lead to prolonged service disruptions for end-users trying to access affected websites.
To mitigate the threat posed by this zero-day vulnerability, security experts recommend implementing appropriate protections such as Web Application Firewalls (WAFs) and DDoS protection measures. Additionally, organizations should ensure that their systems are fully patched with the latest security updates for web server software and operating systems.
This discovery highlights the ongoing need for vigilance in identifying and addressing new threats to internet security. As technology continues to evolve, so too do the tactics employed by cybercriminals seeking to exploit vulnerabilities in widely-used protocols like HTTP/2.
Oct 10, 2023
1,834 words in the original blog post.
On 7th October, 2023, Hamas launched attacks from the Gaza Strip against the south of Israel, initiating a new conflict in the region. Internet traffic was impacted with two networks in the Gaza Strip going offline after the attacks, and two more experiencing outages on October 9. Following these events, there was a surge in general internet traffic in both Israel (~170% growth) and Palestine (100% growth). However, this growth in Palestine was followed by a clear drop in traffic around 08:00 UTC (11:00 local time), possibly due to power outages. Furthermore, there were noticeable increases in cyberattacks targeting Israel, including a DDoS attack with 1.26 billion HTTP requests.
Oct 09, 2023
1,047 words in the original blog post.
To get the best performance, I recommend:
- enable vnethdr
- enable offloads (TSO and USO)
- consider spreading the load across multiple queues and CPUs with multi queue
- consider syscall batching for additional gain of maybe 10%, perhaps try io_uring
- consider customizing the steering algorithm
```
Oct 06, 2023
2,463 words in the original blog post.
Google identified a vulnerability in Google Chrome called "Heap buffer overflow in WebP in Google Chrome." However, it turned out to be a bug deeply rooted in the libwebp library, affecting virtually every application that handles WebP images. The vulnerability allows an attacker to create a malformed WebP image file which can lead to the execution of the attacker's code. This issue had far-reaching consequences and affected a vast array of software and users of the WebP format. Cloudflare has updated its services and encouraged all applications supporting WebP images to update as well, emphasizing the importance of keeping browsers, apps, and operating systems up to date with security patches.
Oct 05, 2023
1,335 words in the original blog post.
Cloudflare has been recognized as one of the Top 100 Most Loved Workplaces in 2023 by Newsweek and the Best Practice Institute (BPI) for the second consecutive year. The company focuses on creating a safe and empowering work environment, with a mission to help build a better internet. Cloudflare emphasizes transparency, innovation, and giving back to the community through various programs. With flexible working arrangements and comprehensive benefits, the company aims to support employee wellbeing both inside and outside of the workplace.
Oct 05, 2023
1,021 words in the original blog post.
Waiting Room adds multi-host and path coverage, unlocking broader protection and multilingual setups
Cloudflare’s Waiting Room feature is now available for multi-path and multi-hostname setups, allowing greater flexibility in configuring waiting rooms across different pages or subdomains of your website. This update enables users to apply the same waiting room rules to multiple paths and hostnames without needing to create separate configurations for each one. The new feature also includes support for multi-language templates, making it easy to adapt waiting room messages to different locales. Additionally, we have introduced a unique cookie suffix requirement to prevent overlapping cookies when using this feature across multiple waiting rooms. This ensures that visitors are routed to the correct waiting room based on their location within your website.
Oct 04, 2023
2,548 words in the original blog post.
On October 4th, 2023, Atlassian disclosed a zero-day vulnerability named "Privilege Escalation Vulnerability in Confluence Data Center and Server" (CVE-2023-22515), affecting their Confluence Server and Data Center products. Cloudflare was notified of the issue before the advisory's publication, working with Atlassian to apply protective WAF rules for all customers. The vulnerability allows an attacker to create unauthorized administrator accounts on public Confluence instances, assessed by Atlassian as critical; however, no CVSS score has been released yet. More information can be found in the security advisory, listing affected versions of Confluence Server.
Oct 04, 2023
160 words in the original blog post.
Cloudflare's 1.1.1.1 DNS resolver service experienced an outage due to a parsing error when loading the new root zone file containing the ZONEMD record, which is used for verifying the authenticity and integrity of the data. The incident affected approximately 2% of all DNS queries handled by Cloudflare during that period. The issue was resolved after disabling the static_zone feature in the resolver server.
Recommendations:
- Ensure regular testing and updates of libraries used in critical systems to handle changes in input formats.
- Implement a mechanism to detect when stale data is being served, especially for critical systems like DNS.
- Regularly review and evaluate existing architectures, processes, and test coverage to identify potential vulnerabilities or areas of improvement.
Oct 04, 2023
1,915 words in the original blog post.
Today, Cloudflare is announcing the general availability of Magic WAN Connector, an integral part of its Secure Access Service Edge (SASE) platform, Cloudflare One. The Magic WAN Connector is a software solution that can be pre-installed on hardware certified by Cloudflare and is entirely managed from the Cloudflare One dashboard. It enables organizations to migrate away from legacy private circuits and utilize Cloudflare's network as an extension of their own, offering simplified connectivity, enhanced security, and improved observability. The Magic WAN Connector aims to streamline SASE transformation by reducing complexity and potential integration challenges through a unified single-vendor platform.
Oct 03, 2023
1,329 words in the original blog post.
In the latest developments at Cloudflare, a wide range of new features and products have been announced as part of their 8th Birthday Week celebrations. These include AI Gateway to provide developers with more control over their AI apps, higher storage limits for databases, browser rendering API for serverless automation, partnership with Microsoft Edge on VPN provision, improvements in the playground feature, and enhanced privacy controls via Encrypted Client Hello standard. Furthermore, Cloudflare Workers Launchpad Funding Program has been extended to include 5 spots specifically reserved for startups using AI features from recent announcements.
Oct 02, 2023
902 words in the original blog post.