560 blogs tracked4,950 posts indexed

#application-security

8 posts · 2 companies · newest first

4

We tested our own WAF with frontier AI models. Here’s what we found (opens on the source site)

We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an authorized staging environment and discovered detection gaps worth fixing. Here’s how the loop worked, what got through, and what we did about it.

aiai-wafexcerpt only · body stays at the source
From the web
6

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts (opens on the source site)

A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.

aiapplication-securityexcerpt only · body stays at the source
From the web
7

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting) (opens on the source site)

Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, preferring post-quantum connections wherever the origin supports it.

From the web
8

BotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents (opens on the source site)

Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission editing, and a behavior model so operators can accurately declare how their bots use content.

ai-botsapplication-securityexcerpt only · body stays at the source
From the web
8 shown

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.