Tag Cloudflare

Threats to the Internet from Misissued Certificates for 1.1.1.1 DNS Service

Potential Security Breach Due to Misissued TLS Certificates A recent alarming security discovery has raised concerns about the vulnerabilities inherent in the public key infrastructure (PKI) supporting internet trust. The precise details surrounding the organization or individual responsible for acquiring unauthorized credentials remain unclear, as representatives from Fina have not…

Read MoreThreats to the Internet from Misissued Certificates for 1.1.1.1 DNS Service

Cloudflare Added to List of Salesloft Drift Breach Victims

Cybercrime, Fraud Management & Cybercrime, Identity & Access Management Extent of Breach Still Unfolding; Reports Indicate Hundreds of Organizations Impacted Mathew J. Schwartz (euroinfosec) • September 3, 2025 Image: Shutterstock A series of data breaches linked to the theft of access tokens from the marketing software provider Salesloft’s Drift AI…

Read MoreCloudflare Added to List of Salesloft Drift Breach Victims

Cloudflare Defends Against Record-Breaking DDoS Attack of 11.5 Tbps

Cloudflare has successfully mitigated an unprecedented DDoS (Distributed Denial of Service) attack, with a peak bandwidth of 11.5 terabits per second, which lasted approximately 35 seconds without causing any disruption to online services. In what marks a significant milestone in cybersecurity defenses, Cloudflare effectively countered the largest recorded DDoS attack…

Read MoreCloudflare Defends Against Record-Breaking DDoS Attack of 11.5 Tbps

Cloudflare Acknowledges Data Breach Associated with Salesloft Drift Supply Chain Compromise

Cloudflare Confirms Impact from Salesloft Drift Breach On Tuesday, Cloudflare disclosed its involvement in the Salesloft Drift breach, confirming that cybercriminals obtained 104 API tokens associated with its platform. Despite the breach, Cloudflare’s security team, led by Sourov Zaman, Craig Strubhart, and Grant Bourzikas, reported no detected suspicious activity linked…

Read MoreCloudflare Acknowledges Data Breach Associated with Salesloft Drift Supply Chain Compromise

Cloudflare Confirms Data Breach: Customer Information Compromised Through Salesforce Instances

Cloudflare has publicly acknowledged a security incident involving its Salesforce environment, traced back to the breach of the Salesloft Drift integration. An advanced threat actor, known as GRUB1, exploited OAuth credentials associated with this integration to extract sensitive support case data. While crucial Cloudflare services remained unaffected, the breach did…

Read MoreCloudflare Confirms Data Breach: Customer Information Compromised Through Salesforce Instances

Cloudflare Confirms Data Breach Associated with Salesforce and Salesloft Drift

Cloudflare has confirmed a data breach linked to Salesforce through the Salesloft Drift integration, resulting in the exposure of customer support case data while keeping core systems intact. In a recent disclosure, Cloudflare acknowledged that a supply chain attack on Salesloft Drift led to the exposure of sensitive customer support…

Read MoreCloudflare Confirms Data Breach Associated with Salesforce and Salesloft Drift

Amazon Disrupts Russian APT29 Watering Hole Attack Targeting Microsoft Authentication

Amazon has effectively thwarted a watering hole campaign orchestrated by the Russian APT29, known as Midnight Blizzard, which exploited compromised websites to undermine Microsoft authentication through malicious redirects. The incident came to light when Amazon’s security team discerned new activities from APT29, a threat group correlated with Russia’s Foreign Intelligence…

Read MoreAmazon Disrupts Russian APT29 Watering Hole Attack Targeting Microsoft Authentication

PoisonSeed Targets CRM Accounts to Initiate Cryptocurrency Seed Phrase Poisoning Attacks

A new threat campaign named PoisonSeed is exploiting compromised login credentials from customer relationship management (CRM) platforms and mass email services to distribute spam messages featuring cryptocurrency seed phrases. This scheme aims to siphon funds from the digital wallets of unsuspecting victims. According to an analysis by Silent Push, the…

Read MorePoisonSeed Targets CRM Accounts to Initiate Cryptocurrency Seed Phrase Poisoning Attacks

Why Cloudflare Prevented Unauthorized AI Access to Web Content

Agentic AI, Artificial Intelligence & Machine Learning, Cloud Security CEO Matthew Prince: Unchecked Scraping Could Undermine the Internet’s Economic Model Michael Novinson (MichaelNovinson) • August 19, 2025 Matthew Prince, Co-founder and CEO, Cloudflare (Image: Cloudflare) Cloudflare has recently implemented a default blockage against unauthorized AI crawlers seeking to access ad-supported…

Read MoreWhy Cloudflare Prevented Unauthorized AI Access to Web Content