Cloudflare developer domains are actively abused by the threat actors for several illicit malicious purposes, as reported by the security analysts at FORTRA.
Recent investigations have uncovered a significant surge in attacks targeting Cloudflare Pages and Cloudflare Workers, two popular platforms used by developers for web deployment and serverless computing.
The abuse of Cloudflare’s services has seen a dramatic increase, with phishing attacks on Cloudflare Pages rising by 198% from 2023 to mid-October 2024.
Similarly, FORTRA analysts noted that Cloudflare Workers experienced a 104% surge in phishing incidents during the same period.
These statistics highlight the growing sophistication of cybercriminals in exploiting trusted platforms.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
Attackers are leveraging Cloudflare’s infrastructure to create convincing phishing sites and execute various malicious activities:-
Several factors make Cloudflare’s platforms attractive to malicious actors:-
While Cloudflare implements various security measures, users and developers must remain vigilant:-
As the cyber threat landscape evolves, it’s crucial for both users and service providers to stay informed and proactive in combating these sophisticated attacks targeting trusted platforms.
Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…