Project Glasswing: what Mythos showed us

2026-05-30T19:24:07Z47decd6798285cd850a972720ff8af27d9994383ea28a393f1a3c72211382baf
acmeai-securityapi-securityclient-side-securitycloudflarecopy-failddosipseclinux-kernelllm-securitymanaged-oauthmcpoauthpingorapost-quantumpost-quantum-roadmaprequest-smugglingsecuritythreat-reportvulnerabilitiesvulnerability-scanner

What happened

A collection of Cloudflare security blog posts (Jan–May 2026) covering operational responses, product launches, and research. Key items include Cloudflare’s response to a critical Linux kernel privilege-escalation (“Copy Fail”), fixes for request-smuggling in Pingora OSS (Pingora 0.8.0), mitigation of an ACME certificate-validation issue, and a 31.4 Tbps DDoS threat report. Strategic and product announcements cover post-quantum IPsec (GA) and a 2029 PQ roadmap, AI/LLM security (AI Security for Apps GA, Cloudy, Client‑Side Security), Managed OAuth and agent-ready auth (RFC 9728), a new Web/APIv

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
47decd6798285cd850a972720ff8af27d9994383ea28a393f1a3c72211382baf
Enrichment time
2026-05-30T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.