Project Glasswing: what Mythos showed us
2026-06-07T19:24:08Z•d6ea1610234c75f2b2cfdef74a8a7416966227dd30d1ceefe97ab11d582513b9
LLM-securityacmeai-securityapi-securitycertificate-validationclient-side-securitycloudflarecopy-failddosipseclinux-kernellog-explorermanaged-oauthmatrixmcpnon-human-identitiesoauthpingorapost-quantumpq-cryptographyprivilege-escalationrequest-smugglingthreat-reportvulnerability-disclosurevulnerability-scanner
What happened
Collection of Cloudflare security blog posts covering multiple disclosures, mitigations, and product launches: response to the “Copy Fail” Linux kernel privilege-escalation disclosure (Cloudflare reports zero customer impact), fixes for request-smuggling in Pingora OSS (Pingora 0.8.0), mitigation of an ACME certificate-validation vulnerability, and broad launches/updates including post-quantum IPsec (GA), AI Security for Apps (GA), Client-Side Security public availability, Managed OAuth for Access, a Web/API vulnerability scanner, and a Q4 2025 DDoS threat report. The bundle also discusses R&D
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- d6ea1610234c75f2b2cfdef74a8a7416966227dd30d1ceefe97ab11d582513b9
- Enrichment time
- 2026-06-07T19:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.