Project Glasswing: what Mythos showed us

2026-05-29T07:24:10Zf8e1f11823711927c4ae9cab07ffbb31c45e2a78bfc94736b7abd38fdfea216b
ACME validationAI securityAPI vulnerability scannerClient-side securityCloudflare GatewayCopy FailDDoSIPsecLLM securityLinux kernelMCPML-KEMOAuthPingoraProject Glasswingaccount abuse protectionauthenticationlog explorermanaged OAuthnon-human identitiespost-quantumprivilege escalationrequest smugglingscoped permissionsvulnerability response

What happened

Collection of Cloudflare security blog posts (Jan–May 2026) covering vulnerability response, post-quantum rollout, AI/LLM security, identity & access improvements, detection tooling, and product security disclosures. Highlights include Project Glasswing (LLM testing on live code), Cloudflare’s response to a publicly disclosed “Copy Fail” critical Linux kernel privilege-escalation (mitigations and zero customer impact), general availability of post-quantum hybrid IPsec (interoperable with Cisco and Fortinet), fixes for request smuggling in Pingora OSS (Pingora 0.8.0), mitigation of an ACME path

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
f8e1f11823711927c4ae9cab07ffbb31c45e2a78bfc94736b7abd38fdfea216b
Enrichment time
2026-05-29T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.