Project Glasswing: what Mythos showed us

2026-05-23T19:24:07Z134892fc8769379813e7cad26e035dbdf7563e05d0f2a3b99c6cfb250a911dcf
account-abuseacmeai-securityclient-side-securitycloudflareddosdsa-ddosipseclinux-kernelllmslog-explorermcpnon-human-identitiesoauthpingorapost-quantumprivilege-escalationrequest-smugglingvulnerability-scanner

What happened

Collection of Cloudflare security blog posts (Jan–May 2026) covering multiple defensive and incident topics: targeted testing of infrastructure with security-focused LLMs (Mythos), mitigation of a critical Linux kernel privilege-escalation (“Copy Fail”) with no customer impact, fixes for request-smuggling in Pingora OSS (Pingora 0.8.0), mitigation of an ACME validation vulnerability, GA post-quantum IPsec (hybrid ML-KEM) and a company PQ roadmap targeting full PQ by 2029, new OAuth/managed-OAuth and non-human identity controls, AI/LLM-focused product launches (AI Security for Apps, Cloudy), a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
134892fc8769379813e7cad26e035dbdf7563e05d0f2a3b99c6cfb250a911dcf
Enrichment time
2026-05-23T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.