Project Glasswing: what Mythos showed us

2026-05-25T19:24:07Ze6756bf82e32c3bfe8c87a24e824f4f7f5560bf765454700fc5e9b1ce3dd4fb6
account-abuseacmeai-securityapi-securitycertificate-validationclient-side-securitycloudflarecopy-failddosipseclinux-kernellog-explorermanaged-oauthoauthpingorapost-quantumpq-cryptoprivilege-escalationrequest-smugglingvulnerability-scanner

What happened

Cloudflare published a set of security-focused updates and investigations covering: mitigation of a recently disclosed critical Linux kernel privilege-escalation called “Copy Fail” (Cloudflare detected, investigated, and mitigated with zero customer impact); disclosure and fixes for request smuggling issues in the open‑source Pingora ingress proxy (fixed in Pingora 0.8.0); a mitigation for an ACME certificate‑validation path vulnerability; new and generally available security features including post‑quantum hybrid IPsec support (interoperable with Cisco/Fortinet) and a company‑wide PQ roadmap,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
e6756bf82e32c3bfe8c87a24e824f4f7f5560bf765454700fc5e9b1ce3dd4fb6
Enrichment time
2026-05-25T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.