Back to Blog

Cloud Security

5 articles on this topic.

Cloud Security25 September 2026

Cloudflare Containers Flaw Exposed Other Customers' Leftover Disk Data

A thin-provisioning misconfiguration let one Cloudflare Containers tenant read residual data from disk blocks previously used by other customers. Cloudflare says it has fixed the flaw and found no evidence of exploitation.

cloudflarecontainersmulti-tenancy
3 min readRead
Cloud Security21 September 2026

Cloudflare Python Workers Hit GA: What the WASM Sandbox Means for Security

After two years in preview, Cloudflare's Pyodide-on-WebAssembly runtime for Python is now production-grade — and it quietly reshapes the isolation model and supply-chain surface teams need to think about.

cloud-securitydevsecopssupply-chain
4 min readRead
AI Security12 August 2026

Context Bombs: Using Prompt Injection to Stop AI Hacking Agents

Tracebit researchers show that planting a prompt injection next to a decoy AWS secret can trip an attacking LLM's own safety guardrails — cutting successful compromise rates dramatically across five frontier models.

ai-securityprompt-injectioncloud-security
4 min readRead
Application Security15 July 2026

FIFA's Broken Access Control Bug Left World Cup Streams Open to Hijack

A researcher who signed up as a football agent found himself inside FIFA's internal platforms — because the authorization checks only ran in the browser.

broken-access-controlpenetration-testingvulnerability-disclosure
4 min readRead
DevSecOps & Infrastructure14 July 2026

Lobste.rs moves to SQLite: a lesson in shrinking your attack surface

The tech-news community site Lobsters has retired MariaDB in favour of SQLite after an eight-year migration effort — a small architectural decision with a useful security lesson about trading network attack surface for single-host risk.

devsecopsattack-surfacearchitecture
4 min readRead