Cloudforce One

79 posts

Cloudforce One banner
Cloudforce One

Cloudforce One

@Cloudforce_One

The official threat intelligence account for @Cloudflare. Follow for threat research, incident assessments, WAF rule updates for emerging threats, and more.

Global Katılım Temmuz 2022
4 Takip Edilen3K Takipçiler
Cloudforce One retweetledi
Cloudflare
Cloudflare@Cloudflare·
Cloudforce One has identified a fundamental shift in the threat landscape: the era of industrialized cyber threats. This era focuses on high-trust exploitation and prioritizes results at all costs. To help organizations counter these changes, today we are releasing the 2026 Cloudflare Threat Report. This report equips organizations with the intelligence they need to build a strategic 2026 roadmap. Get the report: cfl.re/4rbKvER
English
1
4
21
5K
Cloudforce One
Cloudforce One@Cloudforce_One·
Cloudforce One has successfully disrupted the criminal enterprise known as Tycoon 2FA, one of the most popular Phishing-as-a-Service (PhaaS) kit providers, in coordination with industry partners. Read here: cloudflare.com/threat-intelli…
English
0
4
23
3.9K
Cloudforce One
Cloudforce One@Cloudforce_One·
Cloudflare has released new WAF rules addressing the following CVEs to enhance customer protection. SmarterMail - Arbitrary File Upload (CVE-2025-52691) SmarterMail - Authentication Bypass (CVE-2026-23760) developers.cloudflare.com/changelog/post…
English
1
3
10
1.9K
Cloudforce One
Cloudforce One@Cloudforce_One·
Why waste a zero-day when session tokens grant direct access? Why build a custom server when a reputation shield provides nearly untraceable infrastructure with a high delivery rate? Why attack the network when you can use deepfakes to embed insiders directly within your target?
English
0
0
2
190
Cloudforce One
Cloudforce One@Cloudforce_One·
The top metric? Measure of effectiveness. In 2026, the most dangerous actors aren’t the ones with the most advanced code; it’s the ones who can integrate intelligence and technology into a single, continuous system that achieves their mission in the shortest time possible.
English
1
0
2
219
Cloudforce One
Cloudforce One@Cloudforce_One·
Of particular note is the growth in hyper-volumetric DDoS attacks, increasing by over 700% compared to the large attacks we observed in late 2024
Cloudforce One tweet media
English
0
1
3
673
Cloudforce One
Cloudforce One@Cloudforce_One·
Cloudflare has released new WAF rules to improve customer protection against the following vulnerability: React DoS (CVE-2026-23864)
English
3
17
246
26.9K
Cloudforce One
Cloudforce One@Cloudforce_One·
We thank @Vercel for coordinating with us to protect Internet users worldwide.
English
0
0
5
545
Cloudforce One
Cloudforce One@Cloudforce_One·
Upon discovering this attack we worked with the Vercel Trust and Safety Team to ensure the threat was mitigated.
English
1
0
7
627
Cloudforce One
Cloudforce One@Cloudforce_One·
NEW: Threat actors are abusing Vercel to bypass email filters and deploy RMM tools. Our report details a sophisticated Telegram-gated delivery chain used to evade detection. cloudflare.com/cloudforce-one…
Cloudforce One tweet media
English
1
10
22
8.5K
Cloudforce One
Cloudforce One@Cloudforce_One·
Iranian Protest Update: We have observed Iranian authorities targeting Instagram accounts with tools that perform bulk extraction of follower lists and account activity
English
107
815
3.1K
508.3K
Cloudforce One
Cloudforce One@Cloudforce_One·
NEW: Cloudflare detected the largest UDP DDoS attacks of the year—peaking at 29.7 Tbps. Aisuru's "short-burst" UDP carpet-bombing tactics are designed to maximize impact while evading traditional mitigation. cloudflare.com/threat-intelli…
Cloudforce One tweet media
English
4
8
29
11.8K
Cloudforce One
Cloudforce One@Cloudforce_One·
React2Shell has surpassed 1 billion exploitation attempts in just 11 days. We are seeing sustained pressure averaging 4.35M hits per hour — with peaks more than tripling that volume.
Cloudforce One tweet media
English
0
14
88
24.4K
Cloudforce One
Cloudforce One@Cloudforce_One·
Observed activity reflected a clear focus on strategically significant organizations. Highest-density probing occurred against networks in Taiwan, Xinjiang Uygur, Vietnam, Japan, and New Zealand—regions frequently associated with geopolitical intelligence collection.
English
0
1
9
1.9K
Cloudforce One
Cloudforce One@Cloudforce_One·
The two new vulnerabilities affect specific RSC implementations. As of 2025-12-11 20:00UTC, our deployed WAF rules have seen a total of 620.64M hits, with an average of 3.65M hits per hour and a peak of 13.81M hits in a single hour.
Cloudforce One tweet media
English
1
0
12
3.3K
Cloudforce One
Cloudforce One@Cloudforce_One·
UPDATE: Early activity indicates threat actors quickly integrated React2Shell into scanning routines, targeting critical infrastructure like nuclear fuel and uranium. React also disclosed two new vulnerabilities today—Cloudflare protects against all three. blog.cloudflare.com/react2shell-rs…
English
6
21
85
56.7K