The official threat intelligence account for @Cloudflare. Follow for threat research, incident assessments, WAF rule updates for emerging threats, and more.

Global
Joined July 2022
Cloudforce One retweeted
We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits. cfl.re/4oyVQiq
10
18
2
91
12,311
Cloudforce One conducted research into how linguistic deception and file structure can be used to bypass AI-driven code auditors across 18,400 API calls. The findings show that malicious detection rates drop when deceptive comments make up less than 1% of a file and that burying payloads in files larger than 3MB effectively blinds models to malicious intent. Read the full report here: cfl.re/4cPJCxU
1
3
6
5,542
Cloudflare has released a new emergency WAF rule addressing the following CVE to enhance customer protection.   cPanel - Auth Bypass (CVE-2026-41940) developers.cloudflare.com/ch…
1
1
13
1,818
Cloudflare offers proactive protection against CVE-2026-23869 through existing WAF rule aaede80b4d414dc89c443cea61680354.
4
11
151
32,127
Cloudforce One retweeted
Cloudforce One has identified a fundamental shift in the threat landscape: the era of industrialized cyber threats. This era focuses on high-trust exploitation and prioritizes results at all costs. To help organizations counter these changes, today we are releasing the 2026 Cloudflare Threat Report. This report equips organizations with the intelligence they need to build a strategic 2026 roadmap. Get the report: cfl.re/4rbKvER
1
6
23
6,860
Cloudforce One has successfully disrupted the criminal enterprise known as Tycoon 2FA, one of the most popular Phishing-as-a-Service (PhaaS) kit providers, in coordination with industry partners. Read here: cloudflare.com/threat-intell…
3
22
4,226
Cloudflare has released new WAF rules addressing the following CVEs to enhance customer protection. SmarterMail - Arbitrary File Upload (CVE-2025-52691) SmarterMail - Authentication Bypass (CVE-2026-23760) developers.cloudflare.com/ch…
1
3
10
2,086
Introducing the 2026 Cloudflare Threat Report. The top finding? Threat actors have industrialized, and they’re prioritizing ROI at all costs. cloudflare.com/lp/threat-rep…
1
3
7
2,418
The top metric? Measure of effectiveness. In 2026, the most dangerous actors aren’t the ones with the most advanced code; it’s the ones who can integrate intelligence and technology into a single, continuous system that achieves their mission in the shortest time possible.
1
2
297
Why waste a zero-day when session tokens grant direct access? Why build a custom server when a reputation shield provides nearly untraceable infrastructure with a high delivery rate? Why attack the network when you can use deepfakes to embed insiders directly within your target?
2
253
Of particular note is the growth in hyper-volumetric DDoS attacks, increasing by over 700% compared to the large attacks we observed in late 2024
1
3
714
Cloudflare has released new WAF rules to improve customer protection against the following vulnerability: React DoS (CVE-2026-23864)
3
15
6
242
27,088
NEW: Threat actors are abusing Vercel to bypass email filters and deploy RMM tools. Our report details a sophisticated Telegram-gated delivery chain used to evade detection. cloudflare.com/cloudforce-on…
1
9
20
8,543
Upon discovering this attack we worked with the Vercel Trust and Safety Team to ensure the threat was mitigated.
1
6
659
We thank @Vercel for coordinating with us to protect Internet users worldwide.
4
575
Iranian Protest Update: We have observed Iranian authorities targeting Instagram accounts with tools that perform bulk extraction of follower lists and account activity
101
769
95
2,981
509,782
NEW: Cloudflare detected the largest UDP DDoS attacks of the year—peaking at 29.7 Tbps. Aisuru's "short-burst" UDP carpet-bombing tactics are designed to maximize impact while evading traditional mitigation. cloudflare.com/threat-intell…
4
8
29
11,859
.christmas at the top of the naughty list
That email from the .christmas TLD is probably naughty. In 2025, 99.8% of messages from that domain analyzed by @Cloudflare Email Security were classified as malicious or spam. The .lol TLD wasn't much better -- it's no laughing matter. Find out more at radar.cloudflare.com/year-in…
2
1
45
10,144