Website Security & Threat Management
Security Week 2025: in review

Security Week 2025: in review

3/24/2025 · Kim Blight, Adam Martinetti, Alex Dunbrack

What this post added

This post announces several security-related enhancements and features. It details advancements in post-quantum cryptography integration with Cloudflare Zero Trust, automated phishing abuse reporting using threat intelligence and Developer Platform products, and improved account security through social logins and email security for political campaigns. It also highlights enhanced botnet protection, flexible cipher suites, an upgraded URL Scanner, and insights into password reuse. New threat research capabilities include a threat events platform for real-time insights, a unified platform for security posture management, native monitoring with Log Explorer and custom dashboards, new Turnstile Analytics, and extended Cloudflare Radar insights for DDoS, leaked credentials, and bots. For AI security, it introduces Cloudflare for AI, AI models for detecting malicious JavaScript, cryptographic watermarks for AI-generated content, generative AI for deterring AI crawlers, Firewall for AI to protect LLM-powered applications, and improved bot management flexibility. Simplification efforts include Cloudy, an AI agent for configurations, a unified dashboard for application security, improved support for private applications and reusable access policies, and simplified allowlist management with Cloudflare Aegis. API security is enhanced with HTTPS-only for Cloudflare APIs. Data security advancements include detecting sensitive data and misconfigurations in AWS and GCP with Cloudflare One, browser-based RDP for secure third-party access, AI-powered context analysis for Data Loss Prevention accuracy, and DLP Assist for Microsoft Outlook. It also includes a beginner's guide to lattice cryptography for post-quantum preparation and IRAP assessment at the PROTECTED level for the Australian Public Sector.

Read the original post ↗