560 blogs tracked4,950 posts indexed

#attacks

6 posts · 2 companies · newest first

2

A revisit of remote Spectre attacks on Cloudflare Workers (opens on the source site)

In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.

attacksedgeexcerpt only · body stays at the source 764 comments on HN (opens the discussion)
From the web
3

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave (opens on the source site)

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

attackscloudforce-oneexcerpt only · body stays at the source
From the web
4

Some thoughts about Anthropic’s new cryptanalysis results (opens on the source site)

Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results. A few people … Continue reading Some thoughts about Anthropic’s new cryptanalysis results →

academicsaiexcerpt only · body stays at the source
From the web
5

Let’s talk about encrypted reasoning (opens on the source site)

Update August 11, 2026: A group of researchers from all over Europe were inspired by this post, and actually turned it into a real working attack! Check out their writeup and paper here. This is a quick post I wanted to write about a hobby project I spent a weekend on. It has little to … Continue reading Let’s talk about encrypted reasoning →

aiattacksexcerpt only · body stays at the source
From the web
6

Kerberoasting (opens on the source site)

I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy (“oh, why didn’t I think of that”) or else they impress me with the brilliance of their inventors. But there’s also another class of vulnerabilities: these are the ones that can’t possibly exist in important production software, … Continue reading Kerberoasting →

attacksmicrosoftexcerpt only · body stays at the source
From the web
6 shown

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.