Mengenal Black-throated Boatbill: Burung Langka dari Papua

Burung black throated boatbill merupakan salah satu jenis burung eksotis yang menjadi kebanggaan Papua. Saat ini, keberadaan black throated boatbill semakin menarik perhatian para pencinta burung dan peneliti burung di Indonesia maupun dunia. Keunikan perilaku, habitat, dan ciri fisik burung ini membuatnya layak untuk dipahami lebih dalam. Artikel ini akan mengupas secara lengkap berbagai aspek mengenai black throated boatbill, mulai dari karakteristik, habitat, hingga upaya pelestariannya di masa kini.


Karakteristik Fisik Black-throated Boatbill

Black throated boatbill memiliki ciri khas yang mudah dikenali, terutama warna hitam pekat pada bagian tenggorokannya yang menjadi asal nama burung ini. Selain itu, burung ini memiliki bentuk paruh yang unik menyerupai dayung atau “boatbill,” yang memudahkan mereka dalam mencari makan. Ukuran tubuh black throated boatbill tidak terlalu besar, dengan panjang sekitar 12-14 cm. Warna bulunya umumnya didominasi oleh perpaduan antara hijau zaitun pada bagian punggung dan kuning cerah di bawah tubuh.

Bentuk paruh unik ini berfungsi sangat efektif dalam mencari serangga kecil dan larva di batang pohon maupun daun. Black throated boatbill juga dikenal memiliki postur ramping dan gerakan yang lincah saat terbang di hutan-hutan lebat Papua.


Habitat dan Persebaran Black-throated Boatbill di Papua

Black throated boatbill dapat dijumpai hampir di seluruh wilayah hutan dataran rendah Continue reading

How Cloudflare detects MCP traffic and helps secure it

Most companies designed their resource permissions with a human user in mind. A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access. Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed.

An engineer who sees an unexpected result will usually stop and reconsider their actions. Any human being can only click, type, and review so much in a single day. The introduction of AI agents changes both thresholds. Their decisions are nondeterministic, and they can take the same action (or invoke the same tool) indefinitely, without getting tired or stopping for lunch. A plausible — but incorrect — decision can become thousands of incorrect actions before a human notices.

Today, we're announcing new Cloudflare One capabilities to identify inspected MCP traffic, show which users and servers are generating it, and control direct connections on managed network paths. Combined with MCP Server Portals, these controls help administrators see whether agents are using an approved path, or somehow bypassing it.

Model Context Protocol (MCP) servers give agents a common way to Continue reading

Secure all your internal vibe-coded applications — in one click

AI has enabled employees across every team to build applications faster than ever before.

But that speed is also what's keeping every CISO up at night: any employee can build an application, deploy it to the public Internet, and accidentally expose internal work or company data.

Today, we're launching new tools to make it easy to keep your applications hosted on Workers private. You can now apply Cloudflare Access directly to a Worker or to every Worker in your account, so that your applications are behind your company login by default, without relying on each developer to set that up themselves.

You can now:

  • Set a policy at the account level to ensure that all preview and production deployments are behind your company login by default.
  • Set a policy on a single application to ensure authentication is enforced on every domain associated with it, no matter how it's deployed.
  • See exactly who visits your application. Get every authenticated user’s email, name, and groups directly in your code — no JWT (JSON Web Token) validation required. 
  • Deploy an internal platform where every deployment is private by default. We've open-sourced an example: an internal static site platform where every Worker Continue reading

Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal

At a time when looking down at our devices is a ritual in daily life, a natural phenomenon that demands our attention communally upward is a welcome event. On Wednesday, August 12, a total solar eclipse swept from the North Atlantic across Europe, moving over Iceland and northern Spain and Portugal, with a deep partial eclipse over the rest of Western Europe, all near local sunset. This was the first total solar eclipse to cross mainland Europe in twenty years, and it drew millions outdoors to witness the moon pass between Earth and the sun. 

As we saw during the 2026 World Cup and the last total eclipse in 2024, online behavior is noticeably affected when an event at this scale takes place. In this blog post, we’ll use data from Cloudflare Radar to examine how Internet traffic shifted alongside the moon and the sun.  

Internet traffic dips align precisely with maximum obscuration

In the figure above, we measured HTTP request volume in five-minute buckets across the affected countries on eclipse day, and compared it to a normal-day baseline. Each row is a country (except for Alaska) and each column is a five-minute slice of August 12, Continue reading

New Tool – IPsec VPN Configuration Generator (Multi-Vendor, Policy vs Route-Based Interop)

Added a new one to the Network Tools page: an IPsec VPN Configuration Generator for Cisco IOS/IOS-XE, ASA, FortiGate, Palo Alto, Juniper SRX, strongSwan/VyOS, UniFi, and pfSense/OPNsense.

The reason I built this instead of just pointing at vendor docs is the case that actually breaks real deployments: pairing a policy-based peer with a route-based one. A route-based side (VTI/tunnel interface) defaults to a catch-all 0.0.0.0/0 ↔ 0.0.0.0/0 selector, since routing decides what enters the tunnel. A policy-based peer negotiates specific proxy-IDs per subnet pair, pulled straight from its ACL. Put those two together unmodified and phase 2 negotiation just fails — no useful error, just a tunnel that won’t come up.

Certificate Transparency Monitoring is now generally available

Since we launched Certificate Transparency Monitoring in public beta in 2019, we've been emailing subscribers whenever a new TLS certificate appears in a public Certificate Transparency (CT) log for one of their domains. Today, it's turned on for more than 650,000 customer domains. It's an early warning that someone, somewhere, has issued a certificate for a hostname in your zone, giving you a chance to spot a mis-issued certificate early.

It's a useful signal, but it had a noise problem, and we felt it ourselves. Cloudflare issues a large volume of certificates on your behalf: Universal SSL renewals, certificates from Advanced Certificate Manager, and backup certificates. All of them are logged to public CT logs by design, because a certificate that isn't logged won't be trusted by major browsers like Google Chrome and Apple's Safari. So the same transparency that lets you monitor for mis-issuance also surfaces every certificate we issue for you.

And issuance isn't a one-time event. Certificates are short-lived and renew automatically: a single Universal SSL certificate can renew as often as every 60 days, up to about six times a year. That cadence is set to increase, with the CA/Browser Forum having voted to cut Continue reading

MTU Path Test — Find Where a Path Silently Fragments, Hop by Hop

MTU problems are some of the most annoying things to troubleshoot in networking, because they’re usually silent. Small packets sail through fine, everything looks healthy, and then someone complains that a specific app is slow or hanging — and it turns out one link in the path, three hops in, has an MTU 8 bytes smaller than everyone assumed. GRE, IPsec, PPPoE, a VPN overlay, a jumbo-frame config that only got applied to half the path, a VLAN tag quietly adding 4 bytes nobody accounted for, or just two vendors defining and displaying “MTU” differently (L2 vs. L3, tagged vs. untagged) — any of these can quietly clip your effective MTU, and standard ping/traceroute won’t tell you where.

D2DO310: Developing Efficient AI Workflows

Tyler Lynch, Outbound CTO at IBM, joins the show to discuss shifting from “tokenmaxxing” to “valuemaxxing” by optimizing AI agent workflows for efficiency. They explore using Obsidian for persistent agent memory to combat context bloat, the critical importance of secure sandboxing practices, and the strategic use of parallel verification to ensure your agents are performing... Read more »

Compress netlab Lab Topologies with Dot Notation

netlab is using the Python Box library to make the code easier to read1. When I started the project, I hated the way you fetch values from Python dictionaries with stuff like node['ospf']['area']; Python Box lets you write node.ospf.area. Even better2, you can tell Python Box to create intermediate dictionaries as needed. node.ospf.area = 1 will automatically create the node.ospf dictionary.

But wait, there’s more (yes, we’re getting to the topic of today’s blog post): Box lets you use the same dotted notation in YAML files.

HW085: Designing Wi-Fi for High-Density Events

Keith is joined by Ferney Muñoz and Tom Hildebrand to break down the complexities of designing high-density Wi-Fi for large-scale events. They dig into the strategic use of directional antennas, channel reuse techniques, and the necessity of on-site verification to ensure network reliability. They also share practical tips on device roaming, troubleshooting, and cross-team collaboration.... Read more »