The official threat intelligence account for @Cloudflare. Follow for threat research, incident assessments, WAF rule updates for emerging threats, and more.
Global
Joined July 2022
- Tweets84
- Following4
- Followers3.1K
- Likes4
Cloudforce One retweeted
Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. cfl.re/4ahUkeG
Cloudforce One retweeted
We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.
cfl.re/4oyVQiq
Cloudforce One conducted research into how linguistic deception and file structure can be used to bypass AI-driven code auditors across 18,400 API calls. The findings show that malicious detection rates drop when deceptive comments make up less than 1% of a file and that burying payloads in files larger than 3MB effectively blinds models to malicious intent. Read the full report here: cfl.re/4cPJCxU
Cloudflare has released a new emergency WAF rule addressing the following CVE to enhance customer protection.
cPanel - Auth Bypass (CVE-2026-41940)
developers.cloudflare.com/ch…
Cloudflare offers proactive protection against CVE-2026-23869 through existing WAF rule aaede80b4d414dc89c443cea61680354.
Cloudforce One retweeted
Cloudforce One has identified a fundamental shift in the threat landscape: the era of industrialized cyber threats. This era focuses on high-trust exploitation and prioritizes results at all costs.
To help organizations counter these changes, today we are releasing the 2026 Cloudflare Threat Report. This report equips organizations with the intelligence they need to build a strategic 2026 roadmap.
Get the report: cfl.re/4rbKvER
Cloudforce One has successfully disrupted the criminal enterprise known as Tycoon 2FA, one of the most popular Phishing-as-a-Service (PhaaS) kit providers, in coordination with industry partners. Read here: cloudflare.com/threat-intell…
Cloudflare has released new WAF rules addressing the following CVEs to enhance customer protection.
SmarterMail - Arbitrary File Upload (CVE-2025-52691)
SmarterMail - Authentication Bypass (CVE-2026-23760)
developers.cloudflare.com/ch…
Introducing the 2026 Cloudflare Threat Report.
The top finding? Threat actors have industrialized, and they’re prioritizing ROI at all costs.
cloudflare.com/lp/threat-rep…
The top metric? Measure of effectiveness.
In 2026, the most dangerous actors aren’t the ones with the most advanced code; it’s the ones who can integrate intelligence and technology into a single, continuous system that achieves their mission in the shortest time possible.
NEW: The total number of DDoS attacks more than doubled in 2025. And the world-record for largest DDoS attack observed by @Cloudflare was broken 19 times this year, with the current record-holder at 31.4 Tbps
blog.cloudflare.com/ddos-thr…
Cloudflare has released new WAF rules to improve customer protection against the following vulnerability:
React DoS (CVE-2026-23864)
NEW: Threat actors are abusing Vercel to bypass email filters and deploy RMM tools. Our report details a sophisticated Telegram-gated delivery chain used to evade detection. cloudflare.com/cloudforce-on…
Upon discovering this attack we worked with the Vercel Trust and Safety Team to ensure the threat was mitigated.
We thank @Vercel for coordinating with us to protect Internet users worldwide.
Iranian Protest Update:
We have observed Iranian authorities targeting Instagram accounts with tools that perform bulk extraction of follower lists and account activity
NEW: Cloudflare detected the largest UDP DDoS attacks of the year—peaking at 29.7 Tbps. Aisuru's "short-burst" UDP carpet-bombing tactics are designed to maximize impact while evading traditional mitigation. cloudflare.com/threat-intell…
.christmas at the top of the naughty list
That email from the .christmas TLD is probably naughty. In 2025, 99.8% of messages from that domain analyzed by @Cloudflare Email Security were classified as malicious or spam. The .lol TLD wasn't much better -- it's no laughing matter.
Find out more at radar.cloudflare.com/year-in…