This summer, Cloudflare welcomed approximately 60 interns from all around the globe, on a mission to #HelpBuildABetterInternet. Join us as we dive into what we accomplished and our experiences!

Photo: FASTILY (CC BY-SA 4.0) via Wikimedia Commons
Cloudflare, the internet infrastructure and security company, has confirmed that a recent security incident involved unauthorized access to its internal Atlassian server. The company stated that the compromise was limited to its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system, which are used for internal documentation, project tracking, and code repositories.
The incident was first detected on November 14, 2023, when Cloudflare's security team identified a threat actor accessing its self-hosted Atlassian environment. The attacker leveraged a stolen credential to gain initial access. This credential was obtained from a previous compromise of an employee's personal account and was not protected by multi-factor authentication (MFA) at the time of the initial breach.
Upon discovering the unauthorized activity, Cloudflare initiated an immediate investigation and containment process. The company confirmed that the attacker accessed its Confluence, Jira, and Bitbucket systems. Specifically, the attacker gained access to a limited number of source code repositories within Bitbucket.
Cloudflare emphasized that the incident did not impact its customer-facing systems or data. The company's products and services, including its global network and customer data, remained secure and operational throughout the event. There was no evidence of data exfiltration from customer systems or any compromise of Cloudflare's production environment.
The company's internal investigation revealed that the attacker attempted to access a console server and a system that housed a digital certificate signing key. However, these attempts were unsuccessful due to Cloudflare's robust security controls and the implementation of hardware security keys, which prevented the attacker from gaining further access or exfiltrating sensitive cryptographic material.
Cloudflare has taken several steps to mitigate the impact of the breach and enhance its security posture. These actions include rotating all potentially compromised credentials, conducting a comprehensive review of its internal systems, and reinforcing its multi-factor authentication policies across all employee accounts. The company also confirmed that it has notified relevant regulatory authorities and law enforcement agencies about the incident.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.