Project Glasswing: what Mythos showed us

2026-05-24T07:24:02Z76133235276c6ac438a2f9cb2c1ae854e2251da6ae10ca9a0b12ecb5fb76f868
account-abuse-protectionacme-validationai-securityapi-securitycertificate-automationclient-side-securitycopy-failddos-reportipseclinux-privilege-escalationllmlog-explorermanaged-oauthmatrix-homeservermcpoauthpingorapost-quantum-cryptographypq-roadmaprequest-smugglingvulnerability-scanner

What happened

Collection of Cloudflare security blog posts (Jan–May 2026) covering multiple product launches, security features, research, and vulnerability disclosures/mitigations. Notable items: response and mitigations for the critical “Copy Fail” Linux kernel privilege escalation (no customer impact reported); disclosure and fixes for request smuggling issues in Pingora OSS (fixed in Pingora 0.8.0); mitigation of an ACME certificate-validation logic vulnerability in Cloudflare automation; general availability of post-quantum hybrid ML‑KEM support for Cloudflare IPsec plus a company PQ roadmap target of

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
76133235276c6ac438a2f9cb2c1ae854e2251da6ae10ca9a0b12ecb5fb76f868
Enrichment time
2026-05-24T07:24:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.