craig strubhart
539 posts

craig strubhart retweetledi

AI deepfakes. Laptop farms. MFA bypass.
Inside the 2026 Cloudflare Threat Report, we break down how cybercrime is becoming industrialized (and how attackers are using AI).
With Brian Carter and Chris Pacey.
🎧 Full episode + subscribe:
ThisWeekinNET.com
English
craig strubhart retweetledi

Super proud to join many friends and colleagues in saying enough is enough: zerodayclock.com
We've somehow accepted mediocre as the norm.
Respect to Sergei Epp at @sysdig for doing this
English
craig strubhart retweetledi

we had a pretty bad security vulnerability in OpenCode that we patched on friday
the web frontend supported a ?url= parameter to let it connect to servers you may be running else where
Albert Pedersen (security researcher at cloudflare) reported to us that he could take advantage of it to point to an evil server that served up fake sessions that contained markdown with inline scripts
then you could be sent a link like http://localhost:4096?url=evilserver which if you clicked could then run commands on your computer through the terminal APIs
we were able to remote patch the url parameter out on friday but you should update either way to get the following additional fixes:
- opencode does not run a server without explicitly passing in flags
- it serves frontend with CSP headers that prevent inline scripts
- even when opting into the server you are warned if you don't pass OPENCODE_SERVER_PASSWORD
full advisory:
github.com/anomalyco/open…
English
craig strubhart retweetledi

Come join my team! I'm hiring a Senior Red Team Consultant at Mandiant (part of Google CLoud). This role is netsec-focused and must be based in USA.
google.com/about/careers/…
English
craig strubhart retweetledi
craig strubhart retweetledi

Cloudflare Containers are now available in public beta. Deploy simple, global, and programmable containers alongside your Workers: cfl.re/4kNjs06
English
craig strubhart retweetledi

If you want to be a PM on @Cloudflare Workers platform please DM @ritakozlov @elithrar @williamallen @irvinebroque or anyone else on the team. We have a lot to ship 🚢 this year and need help making the platform delight developers everywhere!
English
craig strubhart retweetledi

Almost made it out of the building w/ the Developer Week announcements but when I looked down they'd been redacted. I think they're onto me.
p.s. follow @ritakozlov @rickyrobinett @threepointone @irvinebroque @_mchenco @thomasgauvin @dok2001 and @CloudflareDev — 10 days to go!

English

@Codeman10 Got to be more to this story, hate to be a Mavs fan right now
English

That exactly the way I expected the bears to finish that game. #gobears
English
craig strubhart retweetledi
craig strubhart retweetledi














