VulnerabilityCloudflare Blog·2 months ago

Defend against frontier cyber models: Cloudflare's architecture as customer zero

In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare's customer zero.

VulnerabilityCloudflare Blog·3 months ago

Project Glasswing: what Mythos showed us

In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.

VulnerabilityCloudflare Blog·3 months ago

How Cloudflare responded to the “Copy Fail” Linux vulnerability

When a critical Linux kernel privilege escalation vulnerability became public, Cloudflare's security and engineering teams rapidly detected and investigated the threat across their infrastructure. The company confirmed that the vulnerability resulted in zero customer impact and no evidence of malicious exploitation in their global fleet.