Sourcetrail iconSourcetrailSep 30, 2026 ~7 min source read

Cloudflare’s Year in Review: security fixes, public CA plans, DNS memory savings, and new developer tools

Cloudflare used its 16th anniversary to summarize platform changes: AI-driven traffic shifts, a container storage vulnerability that was fixed, plans for a public certificate authority including post-quantum support, a DNS redesign that saved about 100 TB of RAM, and several new developer-facing tools.

Cloudflare’s Busy Year: Security, Public CA, DNS Cache, Agent Tools

Share this story

Send the public story page.

Useful takeaways from this story.

Cloudflare reported a shift toward automated traffic: agents overtook human browsing in May 2026 and may grow much larger over five years.

A Rust-based DNS redesign cut Cloudflare’s memory usage by roughly 100 TB for the DNS cache.

# Snapshot: what changed Cloudflare published a retrospective at its 16th anniversary describing how the web and Cloudflare's platform have shifted since its founding. The post covers traffic trends, a security incident in container storage, infrastructure optimizations that freed large amounts of memory, a public CA initiative, and several new developer tools and platform experiments.

# Traffic and the rise of automated agents Cloudflare says the web entered a rapid change around mid-2025 after a long flat period. Two concrete trends matter:

  • A surge of new sites and creators using tooling that lets people build and deploy apps without deep programming skills. Cloudflare's platform now serves more than 7 million developers.

# Security: container storage issue and adaptive WAF testing

Cloudflare addressed the problem in stages. It turned block wiping back on for new allocations (stopping the reported technique), then retired affected disks, cleared caches, drained hosts during quiet hours, and restarted servers. The researchers confirmed the proof-of-concept no longer worked on Sept 14, and Cloudflare completed cleanup on Sept 19 before disclosing the issue publicly a few days later.

# Infrastructure work: DNS cache and memory savings Cloudflare redesigned its DNS cache and said the change saved about 100 TB of memory. The work leaned on Rust optimizations. The DNS savings are presented alongside other Rust-related efficiency stories within Cloudflare's recent engineering work.

# Product and platform updates Cloudflare announced several developer-facing updates and experiments:

  • cf CLI: a command-line tool for interacting with Cloudflare services.
  • Turnstile Spin: a new product variant related to their bot/challenge service.
  • EmDash migration: internal migrations to new systems.
  • Experimental Rust/Emscripten support on Workers: exploring new runtime options for edge code.
  • Public Certificate Authority: Cloudflare plans to offer a public CA that will issue TLS certificates and support post-quantum cryptographic material.

# What this means for site operators and developers

  • Track Cloudflare's public CA plans if you manage TLS procurement or require post-quantum certificates.
  • Take advantage of new tools like cf CLI and experimental runtimes to test deployments and performance on Workers.

# Bottom line

More context around this story.

Защита сайта от ботов: 6 лет практики фильтрации трафика
Habr iconHabrSep 5, 2026

Защита сайта от ботов: 6 лет практики фильтрации трафика

Практический разбор шести лет работы с автоматизированным трафиком: от первых поведенческих ботов и ручных правил Cloudflare до собственной многоуровневой системы фильтрации и кластерной аналитики. Читать далее

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app