Project Glasswing: what Mythos showed us

2026-05-19T19:24:07Z94415ab02515eaac8883a08f6dbe16d7c9ecda2f0b83e8b26983303775a8ed23
account-abuseacmeai-securityapi-tokenscertificate-validationclient-side-securitycloudflarecopy-failcryptographyddoshybrid-kemincident-responseipsecleast-privilegelinuxllmmanaged-oauthmcpoauthphishing-detection','log-explorer','vulnerability-scanner','api‑pingorapost-quantumprivilege-escalationrequest-smugglingvulnerability

What happened

Collection of Cloudflare security blog updates (Jan–May 2026) covering multiple high-impact incidents, mitigations, product hardening, and roadmap items. Notable items include Cloudflare’s detection and mitigation of a critical Linux kernel privilege-escalation (“Copy Fail”) with no customer impact, fixes for request-smuggling in the open-source Pingora ingress proxy (Pingora 0.8.0), mitigation of an ACME certificate-validation path vulnerability, and a Q4 2025 DDoS report documenting a record 31.4 Tbps attack. Product/security releases and initiatives include generally available post-quantum/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
94415ab02515eaac8883a08f6dbe16d7c9ecda2f0b83e8b26983303775a8ed23
Enrichment time
2026-05-19T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.