
8/21/2023 · Michael Tremante, David Belson, Sabina Zejnilovic
What this post added
This post provides a quarterly update on application security trends observed on the Cloudflare network for Q2 2023. It details the volume of mitigated traffic, the breakdown between WAF and DDoS mitigation, and the increasing reliance on WAF custom rules. It highlights the common use of geolocation fields in WAF rules and the continued exploitation of older CVEs. Specific examples include CVE-2015-1635 for Microsoft IIS and WordPress wp-config.php access attempts.