BTC$85,190+0.77% LTC$69.87+3.93% XMR$543.25+0.03%
TorPortal TorPortalMarkets, mirrors, dark web news
News › Company

News tagged Cloudflare

Every TorPortal story that mentions Cloudflare. 30 stories, newest first. Category: company.

Latest coverage of Cloudflare

Click a headline for the full story or jump to the original.

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
BleepingComputer · Oct 2, 2026 · 7 min read

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level…
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
BleepingComputer · Sep 29, 2026 · 3 min read

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
Cloudflare fixes Containers cross-tenant flaw exposing customer data
BleepingComputer · Sep 27, 2026 · 2 min read

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
OpenAI hacked Australian Medicare govt site, probed data providers
BleepingComputer · Sep 24, 2026 · 4 min read

OpenAI hacked Australian Medicare govt site, probed data providers

OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research…
Placeholder domain used in dev docs now serves ClickFix attacks
BleepingComputer · Sep 23, 2026 · 5 min read

Placeholder domain used in dev docs now serves ClickFix attacks

The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands.
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
The Record · Sep 22, 2026 · 5 min read

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the…
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
BleepingComputer · Sep 22, 2026 · 4 min read

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
Brevo supply-chain attack injected ClickFix scripts on customer sites
BleepingComputer · Sep 17, 2026 · 1 min read

Brevo supply-chain attack injected ClickFix scripts on customer sites

Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.
BambooToken Malware Uses MQTT to Control Windows and Linux
DarkDotWeb · Sep 16, 2026 · 4 min read

BambooToken Malware Uses MQTT to Control Windows and Linux

BambooToken malware has targeted Windows and Linux systems since 2023, using MQTT and Cloudflare to manage infected machines.
Coder's registry infrastructure compromised to push malicious modules
BleepingComputer · Sep 3, 2026 · 2 min read

Coder's registry infrastructure compromised to push malicious modules

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
Why Even the Best Edge Security Still Misses High-Risk Sessions
BleepingComputer · Sep 1, 2026 · 5 min read

Why Even the Best Edge Security Still Misses High-Risk Sessions

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations…
Iranian cyber spies target aviation, fintech developers with new malware
The Record · Sep 1, 2026 · 3 min read

Iranian cyber spies target aviation, fintech developers with new malware

In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
Microsoft warns of TerminalFix attacks deploying reverse tunnels
BleepingComputer · Aug 31, 2026 · 2 min read

Microsoft warns of TerminalFix attacks deploying reverse tunnels

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
Hackers abuse npm mirrors to host phishing redirect pages
BleepingComputer · Aug 25, 2026 · 3 min read

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.
Hundreds of fake Chrome VPN extensions route traffic through a proxy
BleepingComputer · Aug 12, 2026 · 1 min read

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider.
Signal adds new security feature to thwart man-in-the-middle attacks
BleepingComputer · Aug 12, 2026 · 1 min read

Signal adds new security feature to thwart man-in-the-middle attacks

​Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted.
DDoS attacks over 1 Tbps surged fivefold in the second quarter
BleepingComputer · Aug 11, 2026 · 1 min read

DDoS attacks over 1 Tbps surged fivefold in the second quarter

Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year.
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
BleepingComputer · Aug 10, 2026 · 1 min read

OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users

OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation.
How AI-powered phishing killed blocklists for good
BleepingComputer · Aug 5, 2026 · 8 min read

How AI-powered phishing killed blocklists for good

AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense…
N-able warns of N-central auth bypass flaw exploited in attacks
BleepingComputer · Aug 3, 2026 · 1 min read

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
Cyberattack hits Angola’s largest telco hours before landmark stock debut
The Record · Jul 29, 2026 · 3 min read

Cyberattack hits Angola’s largest telco hours before landmark stock debut

Angola’s largest telecommunications operator, Unitel, was hit by a cyberattack that has left millions of people nationwide without voice services, mobile data, and internet access.
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
BleepingComputer · Jul 23, 2026 · 1 min read

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
BleepingComputer · Jul 18, 2026 · 1 min read

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
BleepingComputer · Jul 16, 2026 · 1 min read

New ClickLock macOS malware traps users into revealing login password

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
New Spirals ransomware encrypts victim network in under 24 hours
BleepingComputer · Jul 16, 2026 · 1 min read

New Spirals ransomware encrypts victim network in under 24 hours

A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours.
Google Gemini CLI abused as a hacking agent, malware botnet operator
BleepingComputer · Jul 15, 2026 · 1 min read

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet.
LastPass, Bitwarden users targeted with fake security alerts
BleepingComputer · Jul 14, 2026 · 1 min read

LastPass, Bitwarden users targeted with fake security alerts

LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites.
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
BleepingComputer · Jul 9, 2026 · 1 min read

New Forg365 phishing platform uses AI to target Microsoft 365 accounts

A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
BleepingComputer · Jul 7, 2026 · 1 min read

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

ActiveState explains how GitHub Actions attack chains can evade traditional CI security scanners, why passing a scan doesn't guarantee a secure pipeline, and how organizations can better govern their CI/CD workflows.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
Krebs on Security · Jun 18, 2026 · 14 min read

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers…

← All news