Project Glasswing: what Mythos showed us
2026-05-22T19:24:04Z•63f26ccbfd1ac50ce59360d32a3e85971b553e2852b6ae1f52b3836974734f1d
account-abuseacmeai-securityapi-securityclient-side-securitycloudflarecopy-failddosincident-responseipseclinux-kernelllmlog-explorermanaged-oauthmcpoauthphishingpingorapost-quantumprivilege-escalationrequest-smugglingsecurityvulnerability-scanner
What happened
Collection of Cloudflare security blog posts (Jan–May 2026) covering a range of operational and product security topics: incident response to a publicly disclosed “Copy Fail” Linux kernel privilege-escalation (no customer impact), disclosure and fix for request-smuggling vulnerabilities in Pingora OSS (fixed in Pingora 0.8.0), ACME validation-mitigation, post-quantum readiness for IPsec and a 2029 PQ roadmap, a large DDoS threat report, new AI- and LLM-focused security products (AI Security for Apps, Cloudy, Client‑Side Security), Managed OAuth and non‑human identity protections, an API/Web AI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 63f26ccbfd1ac50ce59360d32a3e85971b553e2852b6ae1f52b3836974734f1d
- Enrichment time
- 2026-05-22T19:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.