Project Glasswing: what Mythos showed us
2026-05-23T19:24:07Z•134892fc8769379813e7cad26e035dbdf7563e05d0f2a3b99c6cfb250a911dcf
account-abuseacmeai-securityclient-side-securitycloudflareddosdsa-ddosipseclinux-kernelllmslog-explorermcpnon-human-identitiesoauthpingorapost-quantumprivilege-escalationrequest-smugglingvulnerability-scanner
What happened
Collection of Cloudflare security blog posts (Jan–May 2026) covering multiple defensive and incident topics: targeted testing of infrastructure with security-focused LLMs (Mythos), mitigation of a critical Linux kernel privilege-escalation (“Copy Fail”) with no customer impact, fixes for request-smuggling in Pingora OSS (Pingora 0.8.0), mitigation of an ACME validation vulnerability, GA post-quantum IPsec (hybrid ML-KEM) and a company PQ roadmap targeting full PQ by 2029, new OAuth/managed-OAuth and non-human identity controls, AI/LLM-focused product launches (AI Security for Apps, Cloudy), a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 134892fc8769379813e7cad26e035dbdf7563e05d0f2a3b99c6cfb250a911dcf
- Enrichment time
- 2026-05-23T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.