Engineering posts about Threat Modeling
Curated summaries and key learnings for engineers working with Threat Modeling.
Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave
The Cloudflare DDoS Threat Report for the first half of 2026 highlights a significant increase in DDoS attack volume, with over 935 network-layer attacks exceeding 1 Tbps mitigated. The report...
How we secure Figma’s internal systems with agents
The article discusses Figma's innovative approach to securing its internal systems through the development of an AI agent that enhances alert triage and forensic investigations. By leveraging a...
Permission isn't purpose: Intent-based authorization in Omnigent
The article presents a detailed examination of intent-based authorization as implemented in the Omnigent platform, highlighting its role in enhancing security by binding user sessions to declared...
Blocking Slow-Burn Attacks: Contextual Policies in Omnigent
The article explores the vulnerabilities of AI agents to slow-burn attacks, where attackers exploit the agent's inability to recognize harmful sequences of actions that appear benign in isolation. It...
Cloudflare proudly joins the UK government's Cyber Resilience Pledge
Cloudflare's commitment to the UK's Cyber Resilience Pledge emphasizes the importance of cybersecurity governance and collective defense against cyber threats. The article outlines the organization's...
Build your own vulnerability harness
This article provides a comprehensive guide on constructing a model-agnostic vulnerability harness for enterprise codebases, emphasizing the importance of interchangeable AI models in enhancing...
AWS Security Agent adds threat modeling, Kiro power and Claude Code plugin, and more
The AWS Security Agent has been enhanced with new features aimed at improving application security throughout the development lifecycle. Key updates include on-demand penetration testing, advanced...
How Dropbox uses MCP and Dash to close the design-to-code security gap
The article outlines how Dropbox addresses the disconnect between security design reviews and code implementation through the integration of Model Context Protocol (MCP) and Dash. It highlights the...
Announcing Claude Compliance API support with Cloudflare CASB
The article announces the integration of the Claude Compliance API with Cloudflare's Cloud Access Security Broker (CASB), enabling organizations to monitor AI application usage for compliance and...
How security teams can report cyber risk to boards
The article outlines the importance of translating cyber risk into financial terms to enable boards to make informed decisions regarding security investments. It emphasizes the need for coherent risk...
Alert Fatigue Is a Business Risk
The article highlights the critical issue of alert fatigue in enterprise security operations, where the overwhelming volume of alerts leads to significant risks as analysts struggle to prioritize and...
Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver
The article outlines Cloudflare's ongoing commitment to privacy regarding its 1.1.1.1 public DNS resolver, emphasizing the importance of trust in handling personal data. It details the independent...