Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AICloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
Cloudflare's H1 2026 DDoS Threat Report reveals a dramatic 519% quarter-over-quarter surge in attacks exceeding 1 Tbps, with the company mitigating 935 such hyper-volumetric attacks in the first half of the year. The threat landscape shifted from botnet floods to DNS-based reflection and amplification attacks, which accounted for 34.3% of all network-layer activity, while geopolitical events like
AIMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has unveiled NatJack, a novel attack methodology that exploits network address translation (NAT) vulnerabilities to hijack TCP sessions, manipulate DNS responses, and compromise network infrastructure. The techniques, demonstrated at Black Hat USA 2026, enable attackers to expose victim IP addresses, exhaust NAT tables, and gain unauthorized access across various
AINew NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has revealed NatJack, a new class of attacks that exploit network address translation (NAT) vulnerabilities to hijack TCP sessions, spoof DNS responses, and compromise network security. Presented at Black Hat USA 2026, the research demonstrates that these vulnerabilities affect multiple independently developed NAT implementations, including Windows systems, indica
AIChinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers at VulnCheck have discovered a factory-installed backdoor in at least 20 router models manufactured by Chinese company Zbtlink. The backdoor, present in all 21 available firmware images spanning over two years, automatically initiates unauthenticated root shell access and attempts to communicate with Chinese servers.
AI15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Security researchers have identified 15 vulnerabilities in TP-Link devices that highlight significant security risks associated with automated zero-trust network provisioning processes. The findings use TP-Link, a major network device manufacturer, as a case study to demonstrate broader industry concerns about automated device onboarding and configuration.
AIHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Microsoft has identified a cyberattack operation called CaptiveCrunch, attributed to Storm-2945 (a sub-cluster of Midnight Blizzard), that compromises hotel Wi-Fi networks to deliver fake browser updates. The malicious updates install CornFlake, a remote access trojan capable of capturing webcam footage, audio recordings, and keystrokes from infected devices. This attack vector specifically target
AIThe Network Has Become the Control Plane for AI Security
Traditional network firewalls have long served as the foundation of cybersecurity by inspecting traffic and blocking threats within a stable model of users connecting to applications. However, the emergence of AI is fundamentally changing this paradigm, requiring network security to evolve beyond conventional packet inspection. The network infrastructure is now becoming the critical control plane
AISweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
A large-scale credential-harvesting campaign has compromised over 30,000 Fortinet devices globally, with attackers successfully compiling working credentials across multiple sectors in nearly 200 countries. The active threat represents a significant security risk for enterprise organizations relying on Fortinet infrastructure for network security.
Introducing the Cloudflare One stack: agent-powered deployment
Cloudflare has launched the Cloudflare One stack, an agent-powered toolkit designed to automate the configuration, deployment, and management of Zero Trust network architectures. The stack provides AI agents with structured knowledge and tools to handle complex migration tasks from legacy SASE vendors like Zscaler and Palo Alto Networks, reducing implementation timelines from months to hours. Buil
AIRoute public traffic to private applications with Cloudflare
Cloudflare is launching Application Services for Private Origins in closed beta, enabling enterprise customers to route public internet traffic to private applications without exposing them publicly. This capability extends Cloudflare's security, performance, and programmability services (WAF, bot management, rate limiting, caching, Workers) to private origins using existing private network connec
AIThe Hidden Security Risk in Modern Networks: The Work Between Tools
Despite increased network visibility through expanded tech stacks and AI-driven automation, organizations continue to face prolonged outages lasting hours with significant financial and reputational consequences. The persistent challenge lies in the gaps between security tools, where manual processes and coordination failures create vulnerabilities that automation alone cannot address.
The Intersection of Encryption and AI
Bruce Schneier reflects on his 2010 Dark Reading essay about cryptography's limitations in securing modern networks, emphasizing that while cryptography has strong mathematical properties favoring defenders, it cannot address most contemporary cybersecurity challenges like DDoS attacks, malware, and network penetration. He traces this argument from his 2000 book 'Secrets and Lies' through today, n
AIPAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
Palo Alto Networks has issued a warning about active exploitation of CVE-2026-0257, a medium-severity authentication bypass vulnerability in PAN-OS and Prisma Access. The flaw, with a CVSS score of 7.8, allows threat actors to bypass authentication mechanisms and establish unauthorized VPN connections through GlobalProtect.
AIAnti-DDoS Firm Heaped Attacks on Brazilian ISPs
Huge Networks, a Brazilian DDoS protection firm, was found to be harboring infrastructure used to launch massive DDoS attacks against Brazilian ISPs through a botnet exploiting vulnerable TP-Link routers. The company's CEO claims the malicious activity resulted from a January 2024 security breach that compromised development servers and his personal SSH keys, suggesting a competitor may be attempt
AIWhen DNSSEC goes wrong: how we responded to the .de TLD outage
On May 5, 2026, DENIC's incorrect DNSSEC signatures for the .de TLD caused widespread DNS resolution failures, potentially affecting millions of German domains. Cloudflare's 1.1.1.1 resolver mitigated the impact through 'serve stale' functionality (RFC 8767) and Negative Trust Anchors (RFC 7646), continuing to serve cached records and temporarily disabling DNSSEC validation for .de domains until D
