Project Glasswing: what Mythos showed us
2026-06-07T07:24:06Z•d4735c04b9a383c03ec8fd192dcdaa83109d38fb5e733b7a4adbbced9cfbccf5
accessacmeai-securityapi-securityclient-side-securitycloudflareddosincident-responseipseclinux-kernelllm-securitylog-explorermanaged-oauthmcpoauthphishingpingorapost-quantumpq-cryptographyprivilege-escalationrequest-smugglingsecurityvulnerabilitiesweb-security
What happened
A collection of Cloudflare security blog posts (Jan–May 2026) covering incident response, vulnerabilities, and product security advances. Highlights include Cloudflare’s mitigation of a critical Linux "Copy Fail" privilege-escalation, fixes for request smuggling in Pingora OSS, remediation of an ACME certificate-validation bug, a record-setting DDoS threat report (31.4 Tbps), and GA launches for AI Security for Apps, post-quantum IPsec (hybrid ML‑KEM), and client-side security tooling. The posts also cover LLM/AI security research (Mythos testing, Cloudy explanations, phishing detection), new/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- d4735c04b9a383c03ec8fd192dcdaa83109d38fb5e733b7a4adbbced9cfbccf5
- Enrichment time
- 2026-06-07T07:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.