We are launching updated community programs, including Cloudflare Ambassadors and Community Engineers, backed by $1M in open-source funding. Learn how we are supporting maintainers and scaling our developer community.

Cloudflare has announced a new initiative to foster its open-source community, introducing a Cloudflare Ambassadors program and a Community Engineers program, alongside an additional $1 million in funding for open-source projects. This new funding brings Cloudflare's total commitment to open-source initiatives to $3.5 million.
The Cloudflare Ambassadors program is designed to recognize and support individuals who are actively contributing to the Cloudflare developer community. These ambassadors will receive exclusive access to Cloudflare teams, early product previews, and opportunities to speak at events. The program aims to empower community leaders to share their expertise and help others engage with Cloudflare's technologies.
Complementing this, the Community Engineers program will involve direct collaboration between Cloudflare engineers and open-source projects. This initiative is intended to provide hands-on support and expertise to projects that are either built on Cloudflare's platform or are otherwise critical to the broader internet ecosystem. The goal is to strengthen these projects and ensure their continued development and stability.
The additional $1 million in open-source funding will be allocated to various projects, with a focus on those that align with Cloudflare's mission of building a better internet. This funding will support development, maintenance, and security enhancements for critical open-source software. Cloudflare has a history of contributing to open-source, including projects like Pingora, its Rust-based HTTP proxy, and its involvement with the Internet Engineering Task Force (IETF) and other standards bodies.
Cloudflare's ongoing commitment to open-source is evident in its previous funding rounds and its active participation in the open-source community. The company emphasizes the importance of open standards and collaborative development for the security and performance of the internet. These new programs and funding are expected to further solidify Cloudflare's role in the open-source ecosystem.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.