Technology
Cloudflare
cloudflare
Recent
Latest Release Posts
Summary
- pvcli CLI open-sourced
- Runs full Oblivious HTTP flows end-to-end
- Apache-2.0 license; contributions welcome
Summary
- ~70% of observed paths show ORIGIN mismatch
- ORIGIN is an early BGP tie‑breaker (lower preferred)
- RFC4271: ORIGIN should not be modified
Summary
- Runs after origin reply, before caching
- Strip or override headers like Set-Cookie and Cache-Control
- Improves cache hit ratio and reduces origin load
Summary
- Baseline = median of prior 4 weeks (per-country, per-minute)
- Use log2(current / baseline) for symmetric, comparable spikes
- Midnight–08:00 local matches produced the largest spikes (often ≥2×)
Summary
- GA: Cloudflare Internal DNS
- Authoritative + recursive on one control plane
- Included with Cloudflare Gateway (Enterprise)
Summary
- Unauthenticated RCE (CVE-2026-63030) blocked
- SQL injection (CVE-2026-60137) blocked
- WAF rules deployed to all proxied customers
Summary
- NTA restored .AL resolution but suspended DNSSEC
- 1.1.1.1 emits EDE 33 to signal Negative Trust Anchors
- EDE 9 exposes the underlying DNSKEY/DS validation failure
Summary
- Session-scoped behavioral detection
- Privacy-first lightweight client-side JS
- Integrates with Turnstile and bot score
Summary
- Set region hints for anycast cloud origins
- Detects anycast via latency speed-of-light check
- Maps cloud regions to optimal primary and fallback upper tiers
Summary
- Adopt ML-DSA now for signatures; don’t wait.
- Specialist PQ schemes trade size, speed, and implementability.
- Design for agility, side‑channel safety, and capacity impacts.
Summary
- Leaderless QuePaxa consensus deployed
- Linearizable global KV and leases
- Majority-based availability across WAN
Summary
- Joined UK Cyber Resilience Pledge
- Blocked 234B threats/day; mitigated 31.4 Tbps DDoS
- Commitments: governance, supply-chain, default security
Summary
- Per-worker tiered cache via Wrangler
- Stale-while-revalidate returns stale responses while refreshing
- Vary-aware variants plus programmatic tag purges
Summary
- edge payment verification via x402
- stablecoin micropayments with sub-second settlement
- rules API plus dashboard and Terraform integration
Summary
- Research program to reduce unnecessary crawling
- Pay Per Use experiments with Ceramic.ai and You.com
- Signals (freshness, traffic, changes) to surface better content
Summary
- Agent traffic >50% of Internet
- 52% of crawler requests are for AI training (June 2026)
- Licensing market emerging but remains bespoke
Summary
- Three-way bot taxonomy: Search, Agent, Training
- robots.txt use=immediate|reference|full content-use signal
- BotBase adds Enterprise bot visibility and detection IDs
Summary
- Attribution Business Insights dashboard released
- Crawl-to-referral ratios by operator (24h/7d/30d)
- Investigate in dashboard; act via Security rules
Summary
- Rollback via step.do options
- Handlers run in reverse step-start order
- Rollbacks are durable and idempotent
Summary
- self-managed OAuth available to all
- blue-green Hydra upgrade with revocation replay
- refresh-token coalescing to avoid invalidation