Project Glasswing: what Mythos showed us
2026-05-19T19:24:07Z•94415ab02515eaac8883a08f6dbe16d7c9ecda2f0b83e8b26983303775a8ed23
account-abuseacmeai-securityapi-tokenscertificate-validationclient-side-securitycloudflarecopy-failcryptographyddoshybrid-kemincident-responseipsecleast-privilegelinuxllmmanaged-oauthmcpoauthphishing-detection','log-explorer','vulnerability-scanner','api‑pingorapost-quantumprivilege-escalationrequest-smugglingvulnerability
What happened
Collection of Cloudflare security blog updates (Jan–May 2026) covering multiple high-impact incidents, mitigations, product hardening, and roadmap items. Notable items include Cloudflare’s detection and mitigation of a critical Linux kernel privilege-escalation (“Copy Fail”) with no customer impact, fixes for request-smuggling in the open-source Pingora ingress proxy (Pingora 0.8.0), mitigation of an ACME certificate-validation path vulnerability, and a Q4 2025 DDoS report documenting a record 31.4 Tbps attack. Product/security releases and initiatives include generally available post-quantum/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 94415ab02515eaac8883a08f6dbe16d7c9ecda2f0b83e8b26983303775a8ed23
- Enrichment time
- 2026-05-19T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.