Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot.

Several independent reports detail a critical vulnerability, CVE-2023-50387, affecting Cloudflare's internal systems. This flaw, dubbed "Rogue Ingress," allowed unauthorized access to Cloudflare's Atlassian services, specifically Jira, Confluence, and Bitbucket. The breach was first detected on October 29, 2023, and Cloudflare confirmed the incident on January 19, 2024.
The attackers exploited a misconfigured service account credential, which had not been rotated following a prior security incident in October 2022. This credential, which was stored in a source code repository, was compromised during the earlier breach but remained active. The attackers gained persistent access to Cloudflare's systems from November 14, 2023, until they were detected and remediated.
Once inside, the threat actors created new user accounts within the Atlassian suite to maintain their access. They accessed Cloudflare's Jira bug database, Confluence wiki, and a self-hosted Bitbucket server. The Bitbucket server contained source code repositories, including those for Cloudflare's identity provider, Access, and its global network.
Cloudflare's investigation revealed that the attackers attempted to log into their corporate network using the compromised credentials but were unsuccessful due to the company's use of hardware-backed security keys, specifically FIDO2-compliant keys. This security measure prevented the attackers from gaining access to Cloudflare's production systems or customer data.
The company stated that no customer data, systems, or services were impacted by this breach. The attackers also did not gain access to Cloudflare's global network, management systems, or data centers. Cloudflare's security team contained the incident by December 15, 2023, and began a thorough forensic analysis.
The compromised credential was initially exposed during a previous incident involving Okta in October 2022. During that event, the service account credential was accessed by a third party. Cloudflare’s failure to rotate this specific credential after the 2022 incident created the vulnerability that led to the "Rogue Ingress" attack.
Cloudflare has since taken several steps to bolster its security posture. This includes rotating all production credentials, segmenting its network further, and enhancing its monitoring and alerting capabilities. The company also emphasized the importance of its hardware security key implementation in preventing a more severe breach.
The incident highlights the critical need for robust credential management and timely rotation, especially after any security event. While the attackers did not achieve their ultimate goal of accessing Cloudflare's production environment, the breach of internal development systems and source code repositories represents a significant security lapse.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early