Cloudflare – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 02 Sep 2025 21:07:53 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Cloudflare – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Cloudflare hit by data breach in Salesloft Drift supply chain attack https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/ https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/#respond Tue, 02 Sep 2025 21:07:53 +0000 https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/

Cloudflare

Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week.

The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens.

Cloudflare was notified of the breach on August 23, and it alerted impacted customers of the incident on September 2. Before informing customers of the attack, it also rotated all 104 Cloudflare platform-issued tokens exfiltrated during the breach, even though it has yet to discover any suspicious activity linked to these tokens.

“Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer’s configuration and could contain sensitive information like access tokens,” Cloudflare said.

“Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel.”

The company’s investigation found that the threat actors stole only the text contained within the Salesforce case objects (including customer support tickets and their associated data, but no attachments) between August 12 and August 17, after an initial reconnaissance stage on August 9.

These exfiltrated case objects contained only text-based data, including:

  • The subject line of the Salesforce case
  • The body of the case (which may include keys, secrets, etc., if provided by the customer to Cloudflare)
  • Customer contact information (for example, company name, requester’s email address and phone number, company domain name, and company country)

“We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks,” Cloudflare added.

“Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations.”

Wave of Salesforce data breaches

Since the start of the year, the ShinyHunters extortion group has been targeting Salesforce customers in data theft attacks, using voice phishing (vishing) to trick employees into linking malicious OAuth apps with their company’s Salesforce instances. This tactic enabled the attackers to steal databases, which were later used to extort victims.

Since Google first wrote about these attacks in June, numerous data breaches have been linked to ShinyHunters’ social engineering tactics, including those targeting Google itself, Cisco, Qantas, Allianz Life, Farmers Insurance, Workday, Adidas, as well as LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

While some security researchers have told BleepingComputer that the Salesloft supply chain attacks involve the same threat actors, Google has found no conclusive evidence linking them.

Palo Alto Networks also confirmed over the weekend that the threat actors behind the Salesloft Drift breaches stole some support data submitted by customers, including contact info and text comments.

The Palo Alto Networks incident was also limited to its Salesforce CRM and, as the company told BleepingComputer, it did not affect any of its products, systems, or services.

The cybersecurity company observed the attackers searching for secrets, including AWS access keys (AKIA), VPN and SSO login strings, Snowflake tokens, as well as generic keywords such as “secret,” “password,” or “key,” which could be used to breach more cloud platforms to steal data in other extortion attacks.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/feed/ 0 56444
Cloudflare Blocks AI Bots by Default, Adds Paywall for Scrapers https://earlybirdsinvest.com/cloudflare-blocks-ai-bots-by-default-adds-paywall-for-scrapers/ https://earlybirdsinvest.com/cloudflare-blocks-ai-bots-by-default-adds-paywall-for-scrapers/#respond Wed, 02 Jul 2025 23:58:04 +0000 https://earlybirdsinvest.com/cloudflare-blocks-ai-bots-by-default-adds-paywall-for-scrapers/

Cloudflare announced that websites using its services will block AI crawlers by default unless the site owner chooses to allow it.

Additionally, Cloudflare is testing a new feature called Pay Per Crawl, which allows websites to charge AI companies whenever their bots access a page.

Will Allen, who oversees AI-related tools at Cloudflare, stated that more than a million websites had already switched on the company’s older AI-blocking tool.

What is Impermanent Loss in Crypto? (Explained With Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Currently, with the new setting turned on by default, even more sites will be protected without requiring additional steps. Allen also noted that Cloudflare can detect bots, even if they attempt to hide their identity, using tools that analyze patterns in their behavior.

Previously, websites used a system called robots.txt to guide bots on what they could and could not access. However, this method depends on companies choosing to follow the rules, and many AI firms do not.

With Cloudflare’s new approach, website owners can have more control over who sees or uses their content. Nicholas Thompson, CEO of The Atlantic, said AI companies have often used content freely, and that may change if they are required to pay or negotiate access.

Meanwhile, Microsoft recently introduced a new AI system, which it claims can outperform doctors when diagnosing complex medical cases. How does the AI system work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/cloudflare-blocks-ai-bots-by-default-adds-paywall-for-scrapers/feed/ 0 45430
Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider https://earlybirdsinvest.com/cloudflare-blocks-record-7-3-tbps-ddos-attack-against-hosting-provider/ https://earlybirdsinvest.com/cloudflare-blocks-record-7-3-tbps-ddos-attack-against-hosting-provider/#respond Fri, 20 Jun 2025 15:56:33 +0000 https://earlybirdsinvest.com/cloudflare-blocks-record-7-3-tbps-ddos-attack-against-hosting-provider/

Cloudflare

Cloudflare says it mitigated a record-breaking distributed denial of service (DDoS) attack in May 2025 that peaked at 7.3 Tbps, targeting a hosting provider.

DDoS attacks flood targets with massive amounts of traffic with the sole aim to overwhelm servers and create service slowdowns, disruptions, or outages.

This new attack, which is 12% larger than the previous record, delivered a massive data volume of 37.4 TB in just 45 seconds. This is the equivalent of about 7,500 hours of HD streaming or 12,500,000 jpeg photos.

The record-breaking DDoS attack
The record-breaking DDoS attack
Source: Cloudflare

Cloudflare, a web infrastructure and cybersecurity giant specializing in DDoS mitigation, offers a network-layer protection service called ‘Magic Transit,’ which was used by the targeted customer.

The attack came from 122,145 source IP addresses spread across 161 countries, with the majority based in Brazil, Vietnam, Taiwan, China, Indonesia, and Ukraine.

The “garbage” data packages were delivered across multiple destination ports on the victim’s system, averaging 21,925 ports per second and peaking at 34,517 ports/second.

This tactic of scattering traffic helps overwhelm firewall or intrusion detection systems, but Cloudflare claims to have ultimately been able to mitigate the attack without human intervention.

Source IP addresses
Source IP addresses
Source: Cloudflare

Cloudflare’s anycast network dispersed attack traffic to 477 data centers in 293 locations, leveraging key technologies such as real-time fingerprinting and intra-data center gossiping for real-time intelligence sharing and automated rule compilation.

Though nearly the entire attack volume came from UDP floods, accounting for 99.996% of the total traffic, there were multiple other vectors involved, including:

  • QOTD reflection
  • Echo reflection
  • NTP amplification
  • Mirai botnet UDP flood
  • Portmap flood
  • RIPv1 amplification

Each vector exploited legacy or poorly configured services. While this was only a tiny percentage of the attack, it served as part of the attackers’ evasion and effectiveness strategy and could also help probe for weaknesses and misconfigurations.

Cloudflare says valuable IoCs from this attack were timely included in its DDoS Botnet Threat Feed, a free service that helps organizations block malicious IP addresses preemptively.

Over 600 organizations have subscribed to this feed, and the internet giant calls any others at risk of massive DDoS attacks to do the same and block the attacks before they reach their infrastructure.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/cloudflare-blocks-record-7-3-tbps-ddos-attack-against-hosting-provider/feed/ 0 43137
Nike's Clone X and Animus NFTs Go Dark After Cloudflare Glitch https://earlybirdsinvest.com/nikes-clone-x-and-animus-nfts-go-dark-after-cloudflare-glitch/ https://earlybirdsinvest.com/nikes-clone-x-and-animus-nfts-go-dark-after-cloudflare-glitch/#respond Sun, 27 Apr 2025 04:42:32 +0000 https://earlybirdsinvest.com/nikes-clone-x-and-animus-nfts-go-dark-after-cloudflare-glitch/

RTFKT, the digital brand Nike shut down in December 2024, ran into trouble on April 24 after images from its Ethereum
ETH


$1,781.66

non-fungible tokens (NFTs) suddenly disappeared.

Collectors noticed that pictures from collections, such as Clone X and Animus, were no longer showing.

Instead, they saw a black background with a short message stating, “This content has been restricted. Using Cloudflare’s basic service in this manner is a violation of the Terms of Service”.

What is Olympus DAO? (OHM Crypto Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The issue was not with the NFTs themselves but with how the images were stored. Since the files were kept off-chain, they relied on a third-party service—Cloudflare—for delivery.

According to Samuel Cardillo, who led RTFKT’s tech team, the problem started when Cloudflare mistakenly downgraded their account to the free version.

Cardillo explained that the team had been planning to move to a different system since December 2024. However, the decision was delayed, and the migration did not begin until April. Once Cloudflare fixed the account issue, the NFT images started to come back online, but it was clear that a longer-term fix was needed.

In an April 24 post on X, Cardillo stated that he is currently working with AR Drive, a tool that connects to the Arweave network. Arweave offers permanent storage, where users pay once and keep their files online for good.

The goal is to migrate all images for Clone X and Animus to Arweave by the end of April.

Meanwhile, Dead Bruv, the team behind a Solana
SOL


$145.31

-based NFT project, plans to sell 100,000 NFTs from their Meatbags series. What is it for? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/nikes-clone-x-and-animus-nfts-go-dark-after-cloudflare-glitch/feed/ 0 33035
RTFKT NFTs Disappear After Cloudflare Glitch Disrupts Image Hosting https://earlybirdsinvest.com/rtfkt-nfts-disappear-after-cloudflare-glitch-disrupts-image-hosting/ https://earlybirdsinvest.com/rtfkt-nfts-disappear-after-cloudflare-glitch-disrupts-image-hosting/#respond Fri, 25 Apr 2025 16:13:15 +0000 https://earlybirdsinvest.com/rtfkt-nfts-disappear-after-cloudflare-glitch-disrupts-image-hosting/

Images tied to the popular Ethereum NFT collections Clone X and Animus temporarily disappeared on April 24, leaving collectors with blank screens and a notice about a terms of service violation.

The glitch follows the closure of RTFKT, the digital studio behind the collections, which was shut down by Nike in December 2024. Whilst ownership and metadata remained secure on the blockchain, the visual assets linked to the tokens became temporarily inaccessible due to a third-party hosting problem.

RTFKT’s former Head of Technology, Samuel Cardillo, has since confirmed efforts are underway to prevent similar disruptions in the future.

RTFKT NFTs Go Dark After Cloudflare Glitch Disrupts Image Hosting
Source: RTFKT

Why did the NFTs disappear?

The images for RTFKT’s Clone X and Animus collections disappeared after Cloudflare downgraded the account responsible for serving the files. The downgrade, which Cardillo said happened a few days before the paid contract was due to expire, resulted in restrictions being applied to the content.

Instead of displaying NFT images, holders saw a generic black screen with a message indicating that the content had been restricted for violating Cloudflare’s terms of service. This occurred because the files were not stored directly on the Ethereum blockchain, but rather hosted off-chain and delivered through Cloudflare’s services.

Whilst the NFTs themselves were unaffected—the tokens, metadata, and ownership records remained on-chain—the incident highlighted the risks of relying on centralised hosting to display NFT content.

RTFKT NFTs Go Dark After Cloudflare Glitch Disrupts Image Hosting
Source: Samuel Cardillo

What’s next for RTFKT?

Although RTFKT as a company was closed by Nike in late 2024, its collections continue to exist and circulate in the secondary market. To safeguard the media assets associated with those collections, Cardillo announced a migration to Arweave, a decentralised storage network that allows users to store files permanently.

Using AR Drive, a tool built to interface with Arweave, the team plans to move approximately 200GB of image data by the end of April. This transition aims to eliminate reliance on services like Cloudflare and ensure that holders can continue to view their NFTs regardless of third-party service interruptions.

The storage move is estimated to cost around $2,800 and is intended to provide a more reliable solution for long-term access to the digital files linked to RTFKT’s NFTs.

]]>
https://earlybirdsinvest.com/rtfkt-nfts-disappear-after-cloudflare-glitch-disrupts-image-hosting/feed/ 0 32776