The Cloudflare Blog – Brought to you by EmDash

You likely noticed the recent redesign of the Cloudflare Blog. We added dark mode, modernized the look and feel, and made a lot of other small improvements along the way.

What you might not have noticed – well, except for those who are more terminally online – is that the redesign was part of a much bigger migration project. On Wednesday, August 12, we moved the blog to EmDash, a content management system (CMS) built especially to work on Astro and with Cloudflare.

We’ll take you into the migration story – what we learned and how EmDash got better – as well as into the benefits we’re already seeing from a new platform.

We are Customer Zero

At Cloudflare, Cloudflare itself is Customer Zero. This means that we use our products. And – in use – we make them better for ourselves and our customers.

This is a very real cultural value at Cloudflare. The burden of proof is on you if you want to use an external vendor. Why can’t that team support you, what gaps are there, why can’t those gaps be filled, and are those “gaps” true requirements?

This preference is even enshrined in our internal Continue reading

NB588: Active Threats Target Siemens PLCs; IBM Chills Qubits With Modular Cryogenics

Take a Network Break! It’s a Red Alert double feature for Oracle’s Internet Directory LDAP server and Cisco’s Secure Workload Software. In tech news, US law enforcement and intelligence agencies release a joint advisory warning of active threats against Siemens PLCs, Marvell wins a deal to make chips for Google that could bring billions in... Read more »

An interactive introduction to the spanning tree protocol

Warning

This post contains interactive examples. To visualize and interact with them, you need to leave your RSS reader.

Imagine you rent office space for a three-day event. You quickly set up a few Ethernet switches and tape some cables on the floor to get everyone online. Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he gets up for coffee. You could add extra cables, but then you’d get a broadcast storm: Ethernet packets that loop and multiply until nothing else gets through.

That’s where the spanning tree protocol (STP) comes in. STP blocks just enough of your spare cables to leave a loop-free tree. When Stan strikes again, it rebuilds the tree in a second, leaving some time for Blobby, your one-person support crew, to reconnect the cable. See for yourself: the diagram below runs a real STP implementation in your browser!

:demo

A1 @0,0 prio=4096
A2 @0,1
A3 @0,2
A4 @0,3

B1 @1,0 prio=8192
B2 @1,1
B3 @1,2
B4 @1,3

C1 @2,0 prio=8192
C2 @2,1
C3 @2,2
C4 @2,3

A1 -- A2 hazard=0
A2 -- A3 hazard=0
A3 -- A4 hazard=0
B1 -- B2
B2 -- B3
B3 -- B4
C1 -- C2  Continue reading

A non-interactive introduction to the spanning tree protocol

Imagine you rent office space for a three-day event. You quickly set up a few Ethernet switches and tape some cables on the floor to get everyone online. Unfortunately, Stan, your clumsiest coworker, kicks out a cable every time he gets up for coffee. Spare cables would fix that, but a loop turns into a broadcast storm: Ethernet packets multiply until nothing else gets through. That’s where the spanning tree protocol comes in: it blocks just enough of the spare cables to leave a loop-free tree, and rebuilds it in a second each time Stan strikes again.

This content is also available as a text version, with interactive demos that run a real implementation directly in your browser!


This video is an experiment.1 Honestly, except for Radia Perlman reading her poem,2 you should read the original article instead. It presents the same content, but you can play with the interactive examples, which are the main contribution. On the other hand, if you happen to like the video, be sure to tell me in the comments!


  1. I thought automated tools would produce this video in a couple of hours. In the end, it was another rabbit hole Continue reading

AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms find real problems at a scale no human team can match. But when you read the findings closely, a pattern emerges: agents talked into refunds, transfers, and data leaks they had standing authority to perform. Patching the prompt fixes one phrasing until the next model update. Constraining the authority fixes the class. The first job belongs to a red team platform. The second belongs to your runtime, and no scanner will do it for you.

In April 2026, General Analysis raised a $10M seed round on the strength of an uncomfortable demonstration: its adversarial agent attacked 55 live customer service bots and compromised 50 of them. Not lab models, but live systems with real customers and real tool access. This post is about the market behind that demonstration: who now automates the attacker’s role, what the attacks keep finding, and why the fix that lasts is runtime policy rather than a better prompt.

What an AI red team agent actually does

A traditional red team Continue reading

Arista cEOS Does Not Apply ACLs to Control-Plane Traffic

When someone starts singing the Use Digital Twins to Test Your Network hymn (or, more recently, tells you how AI agents can do that to validate their ideas), ask them about these minor details. If they persist, point them (not that it would help) to this long list of gotchas.

That list just got longer: Arista cEOS container does not apply inbound ACLs to control-plane traffic (Arista vEOS VM does).

Fakta Unik Denman Cryobrine Corridor di Danau Lake Denman

Danau Lake Denman Basal Cryobrine Corridor merupakan salah satu fenomena alam yang semakin menarik perhatian para ilmuwan dan peneliti dalam beberapa tahun terakhir. Fenomena yang sering disebut dengan istilah denman cryobrine corridor ini merupakan bagian penting dalam studi iklim dan ekosistem ekstrem di Bumi. Artikel ini akan mengupas fakta-fakta unik seputar denman cryobrine corridor yang relevan hingga saat ini dan bagaimana keberadaannya memengaruhi riset ilmiah di berbagai disiplin ilmu.

Pendahuluan: Apa Itu Denman Cryobrine Corridor?

Denman cryobrine corridor adalah sebuah bagian unik dari sistem glester di sekitar Danau Lake Denman yang dikenal dengan kandungan air garam yang tinggi pada suhu yang sangat rendah. Fenomena ini muncul ketika air garam superdingin membentuk sebuah koridor alami di bawah permukaan es. Keunikan dari denman cryobrine corridor terletak pada kemampuan air garam tersebut bertahan dalam kondisi ekstrem tanpa membeku, sehingga menimbulkan potensi ekosistem mikroorganisme unik yang belum banyak dipahami oleh ilmu pengetahuan.

Saat ini, denman cryobrine corridor sangat menjadi fokus riset karena memberikan wawasan baru terkait adaptasi kehidupan di kondisi ekstrem hingga potensi eksplorasi astrobiologi di planet lain yang memiliki kondisi serupa, seperti Mars atau bulan-bulan es di tata surya.

Karakteristik Fisik Denman Cryobrine Corridor

Pada periode terbaru, penelitian menggunakan satelit dan teknologi bawah Continue reading

Misteri Fenomena Clearwater West Shock Vein Zone yang Menarik

Fenomena alam geologi menarik perhatian para ilmuwan dan penggemar sains di seluruh dunia, salah satunya adalah kawasan Clearwater West Shock Vein Zone. Hingga saat ini, fenomena tersebut masih menyimpan banyak misteri yang membuat para peneliti terus mendalaminya. Artikel ini akan membahas secara lengkap dan terbaru tentang fenomena Clearwater West Shock Vein, dari penemuan, karakteristik, hingga implikasi ilmiah dan lingkungan yang relevan pada kondisi saat ini.

Pendahuluan: Apa Itu Clearwater West Shock Vein?

Fenomena Clearwater West Shock Vein merupakan sebuah zona nirkon yang ditemukan di kawah Clearwater West, salah satu dari dua kawah yang saling berdekatan di Quebec, Kanada. Fenomena ini dikenal sebagai salah satu contoh nyata dari struktur geologi yang terbentuk akibat benturan meteorit raksasa ke permukaan bumi. Kawah Clearwater West sendiri membentang sekitar 26 kilometer dan dikenal sebagai salah satu situs krater tipe “dual impact” yang unik.

Zona shock vein atau urat kejut adalah lapisan tipis material yang terbentuk dengan pola patahan dan deformasi ekstrem karena tekanan dan suhu sangat tinggi pada saat terjadi benturan meteorit. Wilayah Clearwater West Shock Vein menjadi sangat penting sebagai lokasi studi untuk memahami lebih jauh mekanisme pembentukan material dan batuan akibat benturan luar angkasa.

Penemuan dan Studi Terkini di Kawah Clearwater West Continue reading

Say it once: introducing Bot Preference Sync

We’re constantly building for the different goals of our customers. Some customers want to optimize for discovery, while others want to protect their content with the strictest security policy. Among these differing policies, there are multiple ways to mitigate bot traffic. Some mechanisms simply state your preference, assuming best intent from crawlers, and other approaches actually lock down content by outright blocking with a Bot Management solution.

We recognize that it's cumbersome to maintain multiple layers of protection on your website. For example, there are cases in which your robots.txt states that a crawler is Disallowed from accessing your website, while your enforcement rules actually don’t block that crawler. When your stated preferences and your enforced rules disagree, some crawlers treat it as a basis to disregard your preferences or try to bypass your enforced rules.

A couple of years ago, Cloudflare announced an easier way to disallow AI training on your website by tackling two of these layers: a managed value of robots.txt that told a fixed list of major Training crawlers not to train on your content, along with edge-enforced blocks to Training crawlers. On July 1, 2026, we launched easier options to manage different kinds Continue reading

From all-or-nothing to task-based OAuth consent

Since June, developers have created thousands of third-party OAuth apps on Cloudflare, with more than a million authorizations since.  

OAuth makes delegated access possible. It lets applications act on a user’s behalf without asking them to handle long-lived credentials or hand over a password. That model works well when an application can describe its access needs with a small set of scopes. 

Developers use OAuth for SaaS integrations, internal tools, CLIs, and agents. Our permission model has become more granular over time to support better scoping of these different workflows. That is great for security, but it makes a purely all-or-nothing consent screen hard to justify.

Cloudflare OAuth already allows clients to request a subset of their configured scopes. But once the client made that request, the user could not narrow it any further on the consent screen. For the user on the consent screen, the experience was still an all-or-nothing one. If an application requested more access than a user was comfortable granting, their only options were to approve the full request, or deny outright. 

MCP servers are a good example of this. An MCP server might request a broad set of permissions, because in Continue reading

Hedge 316: AI Governance

Deploying AI for AI Ops, or even just for general use in your network, is very simple–but we often forget that these kinds of new technologies need to be governed. From privacy through cost, operators need to decide how to govern their AI deployments to control costs, ensure accuracy, measure productivity, and make certain these systems are being used effectively. Colin Cosgrove joins Russ and Tom to look at AI governance.
 

 
download

IPB206: Do IPv6 Mandates Work?

Nick Burgalio and Tom Coffeen discuss a Reddit post that had what appeared to be new federal guidance on IPv6 adoption. While it seems the timelines and guidelines haven’t changed, the post raises questions about the effectiveness of mandates in driving IPv6 adoption. They posit that enabling IPv6 is not just a technical requirement but... Read more »

TCG082: AI News Roundtable – Copyrights, AI Watermarks, and the Open Weight Debate

William Collins and Eyvonne Sharp dig into the latest AI headlines, from the largest copyright settlement in American history to stolen AI models and invisible watermarks on Claude output. Plus, they discuss why so many companies have rallied around NVIDIA’s support for open weight AI models. Our hosts also examine the biggest questions arising from... Read more »
1 2 3 3,898