Engineering posts about Security Auditing
Curated summaries and key learnings for engineers working with Security Auditing.
Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
The Cloudflare DDoS Threat Report for the first half of 2026 highlights a significant increase in DDoS attack volume, with over 935 network-layer attacks exceeding 1 Tbps mitigated. The report...
How we secure Figma’s internal systems with agents
The article discusses Figma's innovative approach to securing its internal systems through the development of an AI agent that enhances alert triage and forensic investigations. By leveraging a...
Permission isn't purpose: Intent-based authorization in Omnigent
The article presents a detailed examination of intent-based authorization as implemented in the Omnigent platform, highlighting its role in enhancing security by binding user sessions to declared...
How Figma stays ahead of vulnerabilities with agents
The article outlines Figma's innovative approach to security by leveraging agents to monitor code quality and detect vulnerabilities throughout the software development lifecycle. It emphasizes the...
Cloudflare proudly joins the UK government's Cyber Resilience Pledge
Cloudflare's commitment to the UK's Cyber Resilience Pledge emphasizes the importance of cybersecurity governance and collective defense against cyber threats. The article outlines the organization's...
Unlocking the Cloudflare app ecosystem with OAuth for all
The article discusses Cloudflare's recent enhancement of its OAuth capabilities, allowing all customers to create and manage their own OAuth applications. It outlines the challenges faced during the...
Build your own vulnerability harness
This article provides a comprehensive guide on constructing a model-agnostic vulnerability harness for enterprise codebases, emphasizing the importance of interchangeable AI models in enhancing...
AWS Security Agent adds threat modeling, Kiro power and Claude Code plugin, and more
The AWS Security Agent has been enhanced with new features aimed at improving application security throughout the development lifecycle. Key updates include on-demand penetration testing, advanced...
How Dropbox uses MCP and Dash to close the design-to-code security gap
The article outlines how Dropbox addresses the disconnect between security design reviews and code implementation through the integration of Model Context Protocol (MCP) and Dash. It highlights the...
Turning Cloudflare’s threat indicators into real-time WAF rules
The article presents a new integration of Cloudflare’s threat intelligence into Web Application Firewall (WAF) rules, allowing security teams to automate the blocking of high-risk IP addresses...
Announcing Claude Compliance API support with Cloudflare CASB
The article announces the integration of the Claude Compliance API with Cloudflare's Cloud Access Security Broker (CASB), enabling organizations to monitor AI application usage for compliance and...
Why AI Security Infrastructure is Now a CMO Priority
The article emphasizes the critical role of AI security infrastructure in modern enterprises, particularly highlighting the launch of Databricks Lakewatch, an innovative security information and...
Labyrinth 1.1: Making End-to-End Encrypted Backups Even More Reliable
Labyrinth 1.1 introduces a new sub-protocol aimed at improving the reliability of end-to-end encrypted backups for Messenger, allowing messages to be securely backed up even in cases of device loss...
How Meta Is Strengthening End-to-End Encrypted Backups
Meta's HSM-based Backup Key Vault is designed to enhance the security of end-to-end encrypted backups for WhatsApp and Messenger. The system utilizes hardware security modules (HSMs) to store...
Alert Fatigue Is a Business Risk
The article highlights the critical issue of alert fatigue in enterprise security operations, where the overwhelming volume of alerts leads to significant risks as analysts struggle to prioritize and...
Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways
The article outlines Meta's strategic approach to migrating to post-quantum cryptography (PQC) in response to the impending threats posed by quantum computing to current encryption standards. It...
Managed OAuth for Access: make internal apps agent-ready in one click
The article outlines Cloudflare's implementation of Managed OAuth to enhance access for internal applications, allowing agents to authenticate seamlessly. It describes the challenges faced when...
Securing non-human identities: automated revocation, OAuth, and scoped permissions
The article addresses the critical need for securing non-human identities in software development, particularly in the context of agentic AI systems. It outlines the risks associated with credential...
Privacy-first connections: Empowering social experiences at Airbnb
The article outlines Airbnb's approach to enhancing user privacy through the implementation of context-aware profile IDs that decouple user identities from their public profiles. By separating...