Motorola has announced
that it will be working with the GrapheneOS Foundation, a producer of a
security-enhanced Android distribution. “Together, Motorola and the
GrapheneOS Foundation will work to strengthen smartphone security and
collaborate on future devices engineered with GrapheneOS
compatibility.“. LWN looked at
GrapheneOS last July.
Version
1.0 of Gram, an “opinionated fork of the Zed code editor“,
has been released. Gram removes telemetry, AI features, collaboration
features, and more. It adds built-in documentation, support for
additional languages, and tab-completion features similar to the Supertab
plugin for Vim. The mission statement for
the project explains:
At first, I tried to build some other efforts I found online to
make Zed work without the AI features just so I could check it out,
but didn’t manage to get them to work. At some point, the curiosity
turned into spite. I became determined to not only get the editor to
run without all of the misfeatures, but to make it a full-blown fork
of the project. Independent of corporate control, in the spirit of Vim
and the late Bram Moolenaar who could have added subscription fees and
abusive license agreements had he so wanted, but instead gave his work
as a gift to the world and asked only for donations to a good cause
close to his heart in return.
This is the result. Feel free to build it and see if it works for
you. There is no license agreement or subscription beyond the open
source license of the code (GPLv3). It is yours now, to do with as you
please.
According to a blog
post on the site, the plan for the editor is to diverge from Zed
and proceed slowly.
Mark your calendars. The Rapid7 2026 Global Cybersecurity Summit returns May 12–13, bringing together security leaders, practitioners, and industry experts for two days of strategic leadership insight and hands-on operational guidance, designed to equip both decision-makers and defenders to build stronger, more resilient security programs.
This year’s theme is Preemptive Security Operations – a shift from reacting to threats to anticipating and neutralizing them before impact.
Security teams are navigating expanding attack surfaces, AI-accelerated threats, relentless alert fatigue, and increasing pressure to do more with less. The 2026 summit is designed to cut through that complexity and focus on what matters most, helping organizations move from reactive defense to confident, proactive operations.
What to expect from Rapid7’s 2026 summit
Whether you’re shaping security strategy at the executive level or defending systems inside the SOC, the summit will deliver actionable insights you can apply immediately.
Day 1 will focus on the big picture. Designed to bring together security leaders, decision-makers, and practitioners around a shared narrative, the first day will explore the paradigm shift shaping modern security operations. Sessions will examine how MDR is evolving beyond monitoring into proactive defense, how exposure management and threat intelligence are converging with it into unified risk strategies, and how AI is changing both attacker capabilities and defender workflows. The emphasis will be on clarity, alignment, and strategic direction, helping organizations rethink how their SOCs operate in an increasingly complex environment.
Day 2 will go deeper. Structured with dedicated tracks for security leaders and frontline practitioners, the second day will provide focused, role-specific content. Leaders will engage with sessions centered on governance, resilience, and executive accountability, while practitioners will dive into real-world detection scenarios, threat hunting methodologies, red teaming insights, and operational playbooks. This two-track approach reflects the reality facing modern security teams: strategy and execution must move forward together.
Why attend Rapid7’s global cybersecurity summit?
The Rapid7 Virtual Cybersecurity Summit is built for today’s reality where speed, clarity, and confidence matter more than ever. This year’s focus on Preemptive Security Operations reflects a shift from reacting to incidents toward anticipating and reducing risk before impact. Preemptive security means unifying visibility across the attack surface, aligning exposure with detection and response, and using AI and intelligence to prioritize what truly matters. It’s about giving security teams the insight and authority to act earlier, reduce uncertainty, and strengthen resilience across the organization.
If 2025 was about reacting faster, 2026 is about acting sooner, so save the date now and be part of the conversation shaping the future of preemptive security operations.
May 12–13, 2026 Rapid7 Virtual Cybersecurity Summit
We show that LLM agents can figure out who you are from your anonymous online posts. Across Hacker News, Reddit, LinkedIn, and anonymized interview transcripts, our method identifies users with high precision and scales to tens of thousands of candidates.
While it has been known that individuals can be uniquely identified by surprisingly few attributes, this was often practically limited. Data is often only available in unstructured form and deanonymization used to require human investigators to search and reason based on clues. We show that from a handful of comments, LLMs can infer where you live, what you do, and your interests—then search for you on the web. In our new research, we show that this is not only possible but increasingly practical.
Organizations carry a growing burden of technical debt — aging codebases, outdated runtimes, and legacy frameworks that slow innovation, increase security risk, and inflate maintenance costs. Addressing this debt requires tackling a wide range of code transformation challenges: version upgrades, runtime migrations, framework transitions, and language translations, all of which must be repeated across multiple codebases. Today, most organizations perform these tasks manually, consuming 20–30% of enterprise software development effort. Even where automation exists, it’s typically narrow in scope and requires significant upfront investment — leaving most organizations unable to scale transformations effectively and, as a result, unable to meaningfully reduce the technical debt that continues to compound over time.
AWS Transform custom addresses this gap — an intelligent AI agent that learns organization-specific code transformations, executes them consistently at scale, and improves from developer feedback, without requiring specialized automation expertise. This blog explores how AWS Transform custom tackles one of the most pressing transformation challenges today.
Managing Lambda Runtime Lifecycles
AWS Lambda follows a runtime deprecation policy that aligns with the end of community long-term support for programming languages, with all current deprecation schedules available in the AWS Lambda runtime documentation. As upstream language maintainers deprecate runtime versions – including Python 3.8, Node.js 14, and Java 8 , organizations face the critical challenge of upgrading hundreds or thousands of Lambda functions before these runtimes reach end-of-life.
When a Lambda runtime reaches end of life, functions lose access to security patches and technical support, leaving applications potentially exposed to known vulnerabilities and compliance risks. Performance degrades as optimizations in newer runtimes go unrealized, and technical debt compounds — the longer you wait, the harder and more expensive the migration becomes.
For organizations managing hundreds or thousands of Lambda functions across multiple runtimes and languages, the effort is amplified by the scale of coordination required, the manual burden of testing and validation, and the reality that upgrade expertise is often siloed within a handful of engineers. It’s a recurring, high-stakes cycle that pulls teams away from building features.
This is exactly the type of repeatable, organization-wide transformation that AWS Transform custom code transformations can automate. The following sections explore how you can use AWS Transform custom to address Python runtime upgrades and demonstrate the automated approach with a practical example.
Sample application
This demonstration uses SAM Python CRUD Sample — an open-source serverless application built with AWS SAM that implements a full CRUD API. The application consists of five Lambda functions that create, read, update, list, and delete activity records. The following walkthrough shows how AWS Transform custom automates Python runtime upgrades by migrating these Lambda functions from a deprecated runtime (Python 3.8) to a modern runtime version (Python 3.13).
Prerequisites
Before beginning the transformation process, verify the following requirements:
AWS Transform CLI installed and configured in your development environment
Authentication with AWS credentials configured locally and proper IAM permissions to call AWS Transform
AWS Transform custom supports both interactive and non-interactive execution (non-interactive mode for CI/CD and batch execution is covered at the end). Launch the CLI in interactive mode with -t to trust all tools, which lets you use natural language to invoke and define transformations:
atx -t
Note : The -t flag trusts all tool executions without prompting for confirmation. This is convenient
for walkthroughs but means the agent can run shell commands automatically. Review the Trust settings for details on controlling tool permissions.
From here, you can use natural language to list and invoke transformations.
>list all the transformations available
This lists all available transformations — both AWS-managed and custom. AWS provides built-in transformations for common tasks like language upgrades (Java, Python, Node.js), SDK migrations, and Graviton migration. You can also create your own custom transformations using natural language, docs, and code samples.
Invoke the transformation by specifying the transformation name AWS/python-version-upgrade and project path. The agent will prompt you for additional inputs like target Python version and codebase path during the flow.
> Run AWS/python-version-upgrade on my project
Step 3: Transformation Planning
Before starting the planning process, you can provide any additional feedback if any. You can say proceed if you don’t have specific preferences.
This will start the planning process, where the agent will analyze all the source files, context, additional guidance and generate a step-by-step comprehensive plan detailing:
Runtime version updates (Python 3.8 → 3.13)
Dependency compatibility checks
Code pattern updates for Python 3.13 compatibility
AWS Lambda configuration changes
Infrastructure as Code changes
The transformation plan is designed to help maintain functionality while leveraging Python 3.13’s improvements.
You can review the plan and provide feedback, or tell the agent to go ahead and execute it.
Step 4: Transformation Execution and Validation
After reviewing the plan, AWS Transform custom executes the transformation automatically, updating:
Lambda runtime configuration
Python version-specific syntax
Dependency versions for Python 3.13 compatibility
Any deprecated function calls
Any Infrastructure as code templates as well
At the end of each step, the agent commits the incremental changes to a local git branch. If build or test errors occur, the agent attempts to self-debug and resolve issues. As a user, you can stop the transformation and provide feedback if necessary. Once all the steps are complete, the agent will produce a summary of changes.
Next, the agent runs a full validation — comparing the executed changes against the plan for any deviations, verifying all exit criteria are met, and running build commands and unit tests to confirm everything passes.
Once the validation is complete, the agent will ask for feedback. You can provide feedback on the execution results and ask the agent to modify/add/remove changes if needed.
Step 5: Verify Changes
Once the validation is complete, the agent summarizes the changes:
You can quit the atx session by issuing /quit in the terminal.
All the changes are committed to a local staging branch. You can also view this by executing following commands
git status
git branch
git diff main <atx-result-staging-...>
With these steps, you can upgrade your Lambda functions which are already running on deprecated runtimes or nearing EOL with reduced manual effort.
Non-Interactive mode
You can also run this transformation in a non-interactive mode with the following command supplying all the information, so that agent can run without asking for any user inputs. This mode is designed for headless execution, CI/CD pipeline integration and bulk execution where no human intervention is available or desired.
atx custom def exec -p . -n AWS/python-version-upgrade --configuration "validationCommands=pytest,additionalPlanContext=The target Python version to upgrade to is Python 3.13" -x -t
Parameter breakdown:
-n AWS/python-version-upgrade: Name of the AWS managed Python migration transformation
-p .: Path to the current directory containing your Lambda function
-t : Trust all tools without prompting
-x : non-interactive headless mode
--configuration : Validation commands to be used after the transformation and additional instructions to the agent . This example, configures the agent to use “pytest” as the validation command after transformation is complete and specifies the target version of python3.13 as additionalPlanContext. This helps agent with additional context during planning of the changes.
You can also specify these parameters in a config.json and execute like below.
config.json file contains all the information about the project repository path, transformation name, build and validation commands to use. Save the below snippet to config.json in the current directory.
{
"codeRepositoryPath": ".",
"transformationName": "python-version-upgrade",
"validationCommands": "pytest",
"additionalPlanContext": "The target Python version to upgrade to is Python 3.13"
}
How to scale this to multiple Lambda function upgrades?
Now that you have successfully used AWS Transform custom to upgrade a single Lambda function, you can scale this to hundreds or thousands of functions across your organization. Central engineering teams can create campaigns through the AWS Transform web application to define the transformation, specify target repositories, and track progress across the organization. For execution at scale, choose the model that fits your environment — both run in your environment, with access to your existing development resources, build systems, and tool chains. You don’t need to move your code anywhere — AWS Transform custom meets you where you are.
Batch script execution — Ideal for teams that want to run transformations directly on developer machines, EC2 instances or existing CI/CD infrastructure. Wrap the AWS Transform custom CLI in a batch processing script that iterates across multiple repositories using a CSV or JSON input file. The script supports both serial and parallel execution modes with configurable job limits, retry mechanisms, and comprehensive logging. Refer to this GitHub repo for the sample batch launcher script and execution instructions.
Containerized execution on AWS — Best suited for enterprise-scale rollouts where you need managed infrastructure, job orchestration, and centralized monitoring. Run transformations using containers deployed on AWS Batch with AWS Fargate. This solution provides a REST API for job submission, automatic IAM credential management, and full Amazon CloudWatch monitoring — all deployable with a single AWS CDK command. To get started, refer to this GitHub repo and blog.
Cleanup
If you followed along with the hands-on example, remove the cloned repository and virtual environment to free up local resources:
deactivate
cd ..
rm -rf ./sam-python-crud-sample
If you created any AWS resources during testing, delete them to avoid ongoing charges.
Conclusion
Keeping Lambda runtimes current is a recurring operational burden that only grows with scale. What starts as a simple version bump quickly compounds into dependency updates, syntax changes, infrastructure modifications, and extensive testing — multiplied across every function in your fleet.
AWS Transform custom turns this into a repeatable, automated workflow. As we demonstrated, upgrading a multi-function Python 3.8 application to Python 3.13 required just a single CLI invocation — the agent can handle planning, code changes, dependency updates, infrastructure configuration, and validation end to end. And with non-interactive mode and the scaled execution options, you can extend this to hundreds of repositories without manual intervention.
To get started:
Install the AWS Transform CLI and try the Python upgrade transformation on one of your own projects.
Amid a slew of telecom and commercial client announcements today designed to align with the opening of Mobile World Congress 2026, AMD is using the show as a backdrop to launch the desktop versions of their Ryzen AI 400 chips. First teased back during CES 2026, the company is finally giving them a proper launch […]
„Нещата не са каквито изглеждат.“ Това според Питър Бъргър е първата мъдрост на социологията. На някои читатели им изглежда, че след като Полковник А. е анонимен, в „Тоест“ не знаем кой е, и просто публикуваме някакви файлове, подхвърлени незнайно от кого. Не бихме постъпили толкова лекомислено. Самоличността на автора е известна на редакцията, както и основанията му да не я разкрива.
Защо решихме, че има смисъл да му дадем думата? В публична среда, в която непрекъснато ни се стоварват активни мероприятия и дезинформационни кампании, трудно ще придобием съпротивителни сили, ако си нямаме понятие от светогледа на хората, които знаят как обществото може да се тласне в една или друга посока. Това не означава да приемаме Полковник А. за чиста монета – и той не е какъвто изглежда.
Светла Енчева, отговорна редакторка за Полковник А.
Днес си спомних един анекдот. За човек, който намира стара маска от времето на пандемията от COVID-19 в джоба на палтото си, усмихва се носталгично и преди да излезе, си нахлузва бронежилетката. Мен ако питате, натам сме се запътили. Само че без усмивката.
Впрочем и когато COVID-19 дойде в България, се усещаше дългата ръка на службите – дори и да не ви се вярва. Някой пита ли се защо се справихме сравнително добре в първата вълна на пандемията, а после оцапахме всичко? Отговорът е прост. Кафявата книжка, уважаеми читатели.
Всеки офицер на ДС я имаше. Официално се наричаше „Наръчник“ – тази стара хубава дума.
Книжката не беше дебела, но беше плътна – и като съдържание, и като смисъл. В нея бяха описани действията при форсмажорни обстоятелства – пожар, наводнение, земетресение, ядрена война. Разделът за епидемията беше ясен. Офицерът поема командването. Отговорността се заявява веднага. Комуникацията се централизира. Един говори. Другите изпълняват. Присъствието е ежедневно – независимо дали има нови данни. Показват се действия: проверки, заповеди, контрол. Експертите от съответните ведомства докладват, но решението остава при командването. В началото на кризата обществото се нуждае не от обяснения, а от ред. Редът се налага бързо. Забавянето ражда слухове. А слухът се разпространява по-бързо от всяка инфекция.
В края на книжката бяха написани телефонните номера на цялото ръководство на страната, включително и на Тодор Живков. За да се обадиш, ти трябваше специален телефон – ВЧ¹. Мнозина се впечатляваха от тези номера. Аз – от факта, че работеха. Налагало ми се е да се обаждам на най-високо място. И вдигаха. А днес министрите ти казват как взели тежкото решение да не си прекратяват отпуската.
Кафявата книжка не се появи случайно. Тя беше дете на страха.
Най-вече на онзи страх, който преживяхме по време на Карибската криза. Най-големият ми кошмар. Днес хората, които не помнят онези времена, когато СССР и САЩ бяха на ръба на ядрена война, нямат ни най-малка представа колко близо бяхме до края на всичко. Не метафорично. Буквално. До онзи миг, в който някой глупак, без значение от коя страна, натиска едно копче и светът, какъвто го познаваме, престава да съществува.
Тогавашните политици бяха воювали. Знаеха какво е война, и бяха наясно, че от нея по-страшно няма. Затова и се размина. Повечето от днешните дори не са помирисвали война. И аз не знам дали, ако пак се озовем толкова близо до ръба, ще ни се размине втори път.
При Куба се разбра, че идеологията не спасява. Спасява подготовката. Сценарият. Студената глава. Оттам тръгна и книжката – за да не мислиш в последния момент и да не импровизираш, когато вече е късно.
В ГДР го бяха разбрали по трудния начин. В края на 60-те години една грипна епидемия ги удари неподготвени. Не фатално, но достатъчно болезнено, за да си направят изводите. Неволята учи. Започнаха да мислят за кризите системно. Не говореха за това. Просто действаха.
Затова и по време на първия етап от пандемията от COVID-19 жителите на бившата ГДР боледуваха по-малко и по-леко от западногерманците. Журналистите си го обясняваха с БЦЖ ваксината – там била задължителна, тук не. Глупости. На Изток просто бяха чели книжката. А ЩАЗИ, както е известно, беше навсякъде. Случайни хора там нямаше.
В началото на пандемията Световната здравна организация лъжеше като за световно –
че маските не трябвало да се носят и че било напълно достатъчно просто да си мием ръцете. Причината беше прозаична – нямаше достатъчно маски дори за медицинския персонал. Но лъжата бе напечатана на плакати, плакатите – преведени на всички езици на ООН. И днес може да ги видите в някои медицински кабинети в Средна Азия, както ми довери един бивш колега.
Кафявата книжка, изглежда, бе чел и Бащицата Борисов – колкото и да твърди, че книги не чете. Същият, от когото уж непрекъснато се опитваме да се отървем, а той все изплува отнякъде и упорито отказва да ни освободи от присъствието си. Понякога се чудя дали тази негова устойчивост не се дължи донякъде и на факта, че макар и тайно, всъщност го харесваме.
Пожарникарят в Бащицата се събуди. Действаше по сценарий, без да философства. Наложи строга карантина – рязко, без пазарлъци. Затвориха се градове, ограничиха се пътуванията. Създаде се щаб и той започна да говори всеки ден – понякога повече, отколкото беше нужно, но говореше. В криза тишината е опасна. Посещаваше болници, строяваше министри, проверяваше складове. Закупиха се маски, тестове, защитни облекла. Когато се появиха ваксините, бяха поръчани и доставени бързо. Дошли с камион за свинско, майтапеха се някои. И за кенгурско да беше – важното е, че ги имаше.
Борисов показа и нещо друго – че държавата може да се грижи за своите. От чужбина започнаха да се прибират хиляди българи. Някои с перипетии, други по-лесно, но се прибираха. Скръцна със зъби на Външното министерство и иначе ленивите посолства внезапно си спомниха, че имат задължения. Започнаха да съдействат на заседналите сънародници. Самолети се организираха, списъци се изготвяха, телефони се вдигаха. За изненада – и не без известна завист – на далеч по-уредени държави, които в първите седмици изглеждаха по-объркани от нас.
В началото системата проработи. Имаше ред. А редът в първата фаза на криза струва повече от идеологията.
После сценарият свърши.
Бившите колеги от КГБ, както обикновено, се престараха. Пандемията се оказа удобен повод да пуснат на свобода слухове и дезинформация, а аз наблюдавах с тъжна ирония колко малко се е променил светът. Само средствата са нови, рефлексите – същите.
Първата ваксина бързо бе превърната в оръжие, а информацията – в инструмент за внушения. Полезните идиоти реагираха по навик и разнесоха най-нелепите измислици. И разбира се, пропагандата прилепна в България без никаква съпротива – както винаги.
В България един вълшебен хирург, който от епидемиология разбира горе-долу толкова, колкото аз от балет, пое ръководството на борбата с пандемията. Може би защото беше генерал. Тук генералите се харесват. А ако същевременно си и професор, нямаш цена. Един иначе кадърен детски епидемиолог пък откри, че му харесва да слуша собствения си глас по телевизията, и щом си отвореше устата, излизаха по две глупости, които се бореха коя първа да бъде чута.
Никой не слушаше никого. Всеки говореше. Всеки обясняваше. Всеки знаеше.
Стана мазало, както обичат да казват днес младите.
Не знам дали сте забелязали, но мазало става винаги, когато непрофесионалисти започнат да раздават указания. Напоследък точно такива говорят за войни, за агресии, за геополитика. Когато хора, които не знаят от кой край се държи пушката, започнат да размахват думи като „неизбежно“, „необходимо“, „справедливо“, мазалото е зад ъгъла.
Като човек, преживял Карибската криза, ме боли от това. Боли ме и да слушам как лекомислено се говори за края на света от хора, които никога не са усещали колко тънка е линията между живота и нищото.
Като гледам какво се случва всеки път, си мисля: може би е време да изтупаме Кафявата книжка от праха, да я обновим и да я преведем на всички езици на Европейския съюз. Няма да е трудно. Та нали всяка глупост, която Комисията бълва, така или иначе се превежда.
А за изпълнението… кадри още имаме.
Защото сме навсякъде.
1 ВЧ (произнася се ве че) – високочестотен телефон. Това е система за свързване по времето на тоталитаризма, до която са имали достъп по-ограничен кръг лица, отколкото до системата, известна като Петолъчка. – Б.р.
Не знаем дали някой пише на полковника (по Маркес), но Полковник А. със сигурност пише на нас. Той държи на своята анонимност и по изключение ще я приемем. Защото в случая разказът е по-важен от автора. Особено когато става дума за миналото, което отказва да си тръгне. Четете с едно (или с няколко) наум.
Return to office has stalled for many, and the “new normal” for what the corporate network means is constantly changing. In 2026, your office may be a coffee shop, your workforce includes autonomous AI agents, and your perimeter is wherever the Internet reaches. This shift has forced a fundamental change in how we think about security, moving us toward a critical new architecture: agile SASE.
For too long, organizations have struggled under a ‘fragmentation penalty,’ juggling a patchwork of legacy hardware and Virtual Private Network (VPN) concentrators. These tools don’t just require massive upfront investment; they create a mountain of technical debt — the cumulative cost of maintaining thousands of conflicting firewall rules, manual patches, and aging hardware that can’t support AI-scale traffic.
First-generation SASE providers promised a cure, but often just moved the mess to the cloud. By treating every data center as an isolated island, they’ve replaced hardware silos with operational silos. The result isn’t a lack of visibility, but a lack of actionability: plenty of data, but no single way to enforce a consistent policy across a borderless enterprise.
Our customers have told us they need an agile and composable platform. This week, we are announcing innovations to prove that modernizing your network is about “achieving escape velocity”: breaking the inertia of legacy systems to propel high-speed business growth.
What is agile SASE?
While zero trust is the set of security principles organizations are evolving to meet, Cloudflare One is the agile and composable SASE platform that makes them possible. Rather than a rigid collection of bolted-on tools, it converges networking and security into a single, global connectivity cloud.
Built natively on a global network spanning over 300 cities, Cloudflare One allows every security check to run on every server simultaneously. This eliminates ‘service-chaining’ — the slow, sequential processing of data through fragmented tools that acts as a bottleneck for other SASE tools that have been “platformized” via acquisition. By using a single-pass architecture, we ensure that security becomes a weightless propellant for your business, not a decelerator.
What to expect this week
Every day this week, we will release technical deep-dives with five core themes:
Monday: The new standard: We start by securing the next decade of the Internet, ensuring your network foundation is future-proof and programmable by default.
Tuesday: Beyond the password: We tackle the evolution of identity, moving trust from simple credentials to comprehensive human and device verification.
Wednesday: Signal over noise: See how we use AI to fight AI, turning a flood of security data into clear, human-readable actions.
Thursday: The autonomous edge: Performance is a security feature. We will dive into how we have engineered away the traditional friction of the corporate network.
Friday: The unified vision: We close the week by showing how the most sophisticated enterprises and partners in the world are standardizing on Cloudflare One to modernize at scale.
Empowering tech-enabled teams
What sets Cloudflare One apart from “black-box” legacy vendors is a commitment to a composable and programmable platform. We are the only SASE provider that runs side-by-side with a native developer platform — Cloudflare Workers. This allows your team to write code that intercepts security events in real-time, moving beyond simple “allow/block” rules to sophisticated, automated operations.
Our customers aren’t just modernizing infrastructure; they’re redefining business defense. By consolidating onto Cloudflare One, they’re clearing the path for faster, safer growth.
Where to begin your SASE journey
We know large enterprises prioritize agility over “big bang” transformations. Most of our customers build momentum by starting with these immediate needs:
Remote access modernization: Replace maintenance-heavy VPNs with a faster, secure experience. Start with clientless access to accelerate zero trust adoption.
Email phishing protection: Use an AI-powered platform to stop Business Email Compromise (BEC) and multi-channel threats before they reach the inbox.
DNS filtering for web protection: Protect hybrid workforces from malicious sites and reduce alert noise for your security team using the world’s fastest resolver, 1.1.1.1.
Safe AI adoption: Discover shadow AI use and govern how your data moves into generative and agentic AI prompts.
Coffee shop networking: Simplify branch networks by treating every office like a remote site, reducing the need for heavy hardware boxes.
Join the connectivity cloud
The next decade of the Internet will be defined by speed, AI, and quantum-level risks. If your SASE provider is still talking about multi-year migration timelines, they aren’t a platform — they’re a bottleneck.
Join us this week and experience the “single-pass” performance difference for yourself. Zero-risk entry starts now: Get started with Cloudflare One for free for up to 50 users, or engage our team to map your large-scale modernization journey.
In the world of cybersecurity, “starting from scratch” is a double-edged sword. On one hand, you have a clean slate; on the other, you face a mountain of configurations, best practices, and potential “gotchas.”
While Cloudflare One has been often cited as one of the easiest-to-use SASE platforms, there is no magic without proper configuration. And while Cloudflare has been striving to simplify complex networking concepts by creating products such as Cloudflare WAN, Magic Transit, and Cloudflare Network Firewall, which simplify and reduce the typical complexity associated with deploying comparable functions from other vendors, the breadth of capabilities provided by Cloudflare One require creation of best-practice policies and templates to achieve the most optimal outcomes.
To make it easy to start taking advantage of Cloudflare’s powerful SASE platform, we have developed a method that ensures customers get the right configuration quickly and easily. We call it Project Helix.
In this post, we’ll dig into the problem of getting the correct customization, and how we built Project Helix to make it simple. That means our customers have access to the most powerful SASE platform out there — and the easiest to onboard.
The complexity barrier: Why a ‘blank slate’ can slow Zero Trust adoption
Cloudflare One is the world’s largest composable platform, and we enable our product teams to release different capabilities when they are ready. That means customers get access to cutting-edge features as soon as possible, but sometimes these features require tweaking settings or attributes that are set in the platform by default.
For example, Cloudflare One provides comprehensive DNS protection, Network Protection, Secure Web Gateway, and Zero Trust Access to any private application included in all of our comprehensive Interna packages. But deploying advanced security capabilities such as Secure Web Gateway, TLS inspection, DLP, AV scanning, etc. may be too disruptive right out of the gate — so a Cloudflare One tenant is typically provisioned with a blank slate. That means that there are many switches one must flip to enable the full power of Cloudflare One.
So we faced a dilemma: How can we help our customers get the right settings, right away?
We started by releasing guides to help administrators get started quickly, wherein they could select a scenario that matches their goals and outcomes.
But we soon realized that that approach did not accomplish the frictionless nirvana we were after. For example, customers who wanted to take advantage of all four scenarios described in the “Get Started” guide would need to step through each of those wizards individually.
In another instance, we released a highly-anticipated capability to connect and secure any private app by hostname. But it was tricky to enable: in addition to flipping a switch in the Cloudflare One settings page, it required customers to change their default split tunnel configuration to include a specific CGNAT range designated for this functionality to be sent to Cloudflare via Cloudflare One Client. We couldn’t easily make this change a default Cloudflare One Client profile, as any change affecting traffic routing on a customer’s network could potentially break existing environments.
For greenfield deployments, we want to be easily able to enable any customer to benefit from this capability without introducing a bunch of friction.
We needed a way to engage the knowledge we have, and use it to navigate the numerous knobs, switches, and policies on behalf of our customers — so they can take advantage of the full breadth of innovation.
Project Helix: Codifying expertise and automation
To achieve this goal, we needed to find a reliable way of taking the amazing brainpower of our Solutions Engineers, Professional Service Engineers, and Partners and enable them to share the best practices they encountered deploying Cloudflare One, whether for production, demos, or proof-of-concepts.
Sharing this knowledge had to be as easy as a push of a button and in a codified format — otherwise we knew it wouldn’t be done consistently. We decided to call it Project Helix, for the way in which it weaves together expertise and automation.
We kicked off the knowledge gathering by asking ourselves what we want customers to experience during the proof of concepts, and we documented all those outcomes. These included enabling baseline security best practice protections across DNS, Network, and HTTP protocols, enabling TLS inspection, QUIC/HTTP3 security for customers (a Cloudflare-exclusive capability for over 3 years now!), deploying Remote Browser Isolation for risky domain categories (such as newly-registered domains), deploying visibility and controls over AI applications the users can access, and elevating the visibility and configuration of the Tenant Control policies that allow customers to restrict their users to accessing only their own instance of SaaS applications such as Office 365, Google Workspace, Dropbox, Box, etc.
We also noted that a frequent point of friction for our customers was splitting out traffic for popular real-time communication apps such as Zoom to go directly to the Internet. And for customers whose users are often traveling, the team assembled a list of widely used captive portals across airlines, hotels, etc., to help ensure a smoother experience for users accessing resources on those private networks in conjunction with the Cloudflare One client.
The old way — manual deployment — has significant drawbacks. Deploying all those policies and configurations manually on a brand-new tenant would take several hours. It would also require copious documentation that would need to be manually maintained and updated. And manual configuration and execution of all these steps is subject to human error, raising questions of consistency.
The technology behind Helix: Terraform and Workers
When we learned that our in-house Cloudflare teams had embraced Terraform to manage the ever-growing number of accounts used to support Cloudflare internal users, we decided to use a similar approach to solve our own dilemma.
We architected scalable and flexible Terraform templates that were programmed to deliver all these settings, configuration snippets, and policies. Once we saw how amazing that outcome was, we wanted to make this easier and more user-friendly for the broader user base.
So the team created a web-based user interface, hosted in Cloudflare Workers and leveraging Cloudflare Containers, to take input parameters and execute Terraform templates in an ephemeral fashion. As there’s no persistent storage used for this solution, it eliminates any potential security risk of storing logs or tokens used in the Terraform provisioning process. This allows anyone, from the most seasoned Solution Engineer to someone who is brand new to Cloudflare One, to deploy the full-functioning baseline configuration with a push a button.
Within a couple of minutes of entering some basic information, the Cloudflare One tenant is fully configured and enabled with advanced security features and most optimal settings. Helix also surfaces a comprehensive list of security policies that we recommend the customer enable –- with a flip of the switch.
We start by deploying a set of robust DNS-based security settings, surfacing policies that allow corporate DNS for zero trust, while blocking security risks and questionable categories from ever being resolved by the DNS. So when you log in to Cloudflare Dash interface, you will see the following DNS policies preconfigured:
We then layer it with robust network policies that protect users and stop malicious traffic across all ports and protocols that you can observe by going to the Network Policies tab in the Dash UI
And finally, we finish this with a broad set of robust HTTP security policies, featuring granular enterprise application tenant controls, securing of AI prompts, and isolating risky domains via Browser Isolation.
All of this is achieved in a matter of minutes, with 100% consistency and immunity to human data-entry errors. All you have to do is to turn these policies on or off to suit your particular needs.
To top it off, the deployment is optimized for maximum interoperability with leading captive portals across airlines and hotels, while also providing an option to easily break out traffic to Zoom to avoid performance issues of tunnelling.
But wait — there was one more thing! Cloudflare internationalized its UI back in 2020, and we wanted to bring the same language-friendliness to all customers and partners across the globe. So we templatized all the object names, policy names, user interactions, etc., within Terraform, and delivered the ability to internationalize deployment of these core best practices and policies in any language.
The impact
The impact of this initiative has been massive. According to Bob Percciacante, a very seasoned Cloudflare One Solutions Engineer, using Helix for one of his proof-of-concepts saved 2–3 weeks of start-up and prep time to configure and verify all the necessary settings and features. He was able to demonstrate all the essential Cloudflare One features to the customer within 15 minutes of deploying a Helix-based configuration.
For the customer, it means they can start enjoying the security of Zero Trust from day one.
Ready to go beyond the blank slate and accelerate your own Zero Trust deployment?
Explore Cloudflare One: Learn more about the Cloudflare One platform and its comprehensive SASE capabilities on our Cloudflare One page.
Contact your Cloudflare account team to experience the best of Cloudflare One deployment at lightning speed!
Every organization approaches security through a unique lens, shaped by their tooling, requirements, and history. No two environments look the same, and none stay static for long. We believe the platforms that protect them shouldn’t be static either.
Cloudflare built our global network to be programmable by design, so we can help organizations unlock this flexibility and freedom. In this post, we’ll go deeper into what programmability means, and how Cloudflare One, our SASE platform, helps customers architect their security and networking with our building blocks to meet their unique and custom needs.
What programmability actually means
The term programmability has become diluted by the industry. Most security vendors claim programmability because they have public APIs, documented Terraform providers, webhooks, and alerting. That’s great, and Cloudflare offers all of those things too.
These foundational capabilities provide customization, infrastructure-as-code, and security operations automation, but they’re table stakes. With traditional programmability, you can configure a webhook to send an alert to Slack when a policy triggers.
But the true value of programmability is something different. It is the ability to intercept a security event, enrich it with external context, and act on it in real time. Say a user attempts to access a regulated application containing sensitive financial data. Before the request completes, you query your learning management system to verify the user has completed the required compliance training. If their certification has expired, or they never completed it, access is denied, and they are redirected to the training portal. The policy did not just trigger an alert — it made the decision.
Building the most programmable SASE platform
The Cloudflare global network spans more than 330 cities across the globe and operates within approximately 50 milliseconds of 95% of the Internet-connected population. This network runs every service on every server in every data center. That means our industry-leading SASE platform and Developer Platform run side by side, on the same metal, making our Cloudflare services both composable and programmable.
When you use Cloudflare to protect your external web properties, you are using the same network, the same tools, and the same primitives as when you secure your users, devices, and private networks with Cloudflare One. Those are also the same primitives you use when you build and deploy full-stack applications on our Developer Platform. They are designed to work together — not because they were integrated after the fact, but because they were never separate to begin with.
By design, this allows customers to extend policy decisions with custom logic in real time. You can call an external risk API, inject dynamic headers, or validate browser attributes. You can route traffic based on your business logic without adding latency or standing up separate infrastructure. Standalone SASE providers without their own compute platform require you to deploy automation in a separate cloud, manually configure webhooks, and accept the round-trip latency and management overhead of stitching together disconnected systems. With Cloudflare, your Worker augments inline SASE services like Access to enforce custom policies, at the edge, in milliseconds.
What programmability unlocks
At its core, every security gateway operates on the same fundamental model. Traffic flows from sources, through policies, to destinations. The policies are where things get interesting, but in most platforms, your options are limited to predefined actions: allow, block, isolate, or quarantine.
We think there is a better way. What if you could invoke custom logic instead?
Rather than predefined actions, you could:
Dynamically inject headers based on user identity claims
Call external risk engines for a real-time verdict before allowing access
Enforce access controls based on location and working hours
Today, customers can already do many of these things with Cloudflare. And we are strengthening the integration between our SASE and Developer Platform to make this even easier. Programmability extensions, like the ones listed above, will be natively integrated into Cloudflare One, enabling customers to build real-time, custom logic into their security and networking policies. Inspect a request and make a decision in milliseconds. Or run a Worker on a schedule to analyze user activity and update policies accordingly, such as adding users to a high-risk list based on signals from an external system.
We are building this around the concept of actions: both managed and custom. Managed actions will provide templates for common scenarios like IT service management integrations, redirects, and compliance automation. Custom actions allow you to define your own logic entirely. When a Gateway HTTP policy matches, instead of being limited to allow, block, or isolate, you can invoke a Cloudflare Worker directly. Your code runs at the edge, in real time, with full access to the request context.
How customers are building today
While we are improving this experience, many customers are already using Cloudflare One and Developer Platform this way today. Here is a simple example that illustrates what you can do with this programmability.
Automated device session revocation
The problem: A customer wanted to enforce periodic re-authentication for their Cloudflare One Client users, similar to how traditional VPNs require users to re-authenticate every few hours. Cloudflare’s pre-defined session controls are designed around per-application policies, not global time-based expiration.
The solution: A scheduled Cloudflare Worker that queries the Devices API, identifies devices that have been inactive longer than a specified threshold, and revokes their registrations, forcing users to re-authenticate via their identity provider.
export default {
async scheduled(event, env, ctx) {
const API_TOKEN = env.API_TOKEN;
const ACCOUNT_ID = env.ACCOUNT_ID;
const REVOKE_INTERVAL_MINUTES = parseInt(env.REVOKE_INTERVAL_MINUTES); // Reuse for inactivity threshold
const DRY_RUN = env.DRY_RUN === 'true';
const headers = {
'Authorization': `Bearer ${API_TOKEN}`,
'Content-Type': 'application/json'
};
let cursor = '';
let allDevices = [];
// Fetch all registrations with cursor-based pagination
while (true) {
let url = `https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/devices/registrations?per_page=100`;
if (cursor) {
url += `&cursor=${cursor}`;
}
const devicesResponse = await fetch(url, { headers });
const devicesData = await devicesResponse.json();
if (!devicesData.success) {
console.error('Failed to fetch registrations:', devicesData.errors);
return;
}
allDevices = allDevices.concat(devicesData.result);
// Extract next cursor (adjust if your response uses a different field, e.g., devicesData.result_info.cursor)
cursor = devicesData.cursor || '';
if (!cursor) break;
}
const now = new Date();
for (const device of allDevices) {
const lastSeen = new Date(device.last_seen_at);
const minutesInactive = (now - lastSeen) / (1000 * 60);
if (minutesInactive > REVOKE_INTERVAL_MINUTES) {
console.log(`Registration ${device.id} inactive for ${minutesInactive} minutes.`);
if (DRY_RUN) {
console.log(`Dry run: Would delete registration ${device.id}`);
} else {
const deleteResponse = await fetch(
`https://api.cloudflare.com/client/v4/accounts/${ACCOUNT_ID}/devices/registrations/${device.id}`,
{ method: 'DELETE', headers }
);
const deleteData = await deleteResponse.json();
if (deleteData.success) {
console.log(`Deleted registration ${device.id}`);
} else {
console.error(`Failed to delete ${device.id}:`, deleteData.errors);
}
}
}
}
}
};
Configure the Worker with environment secrets (API_TOKEN, ACCOUNT_ID, REVOKE_INTERVAL_MINUTES) and a cron trigger (0 */4 * * * for every 4 hours), and you have automated session management. Just getting a simple feature like this into a vendor’s roadmap could take months, and even longer to move into a management interface.
But with automated device session revocation, our technical specialist deployed this policy with the customer in an afternoon. It’s been running in production for months.
We’ve observed countless implementations like this across Cloudflare One deployments. We’ve seen users implement coaching pages and purpose justification workflows by using our existing redirect policies and Workers. Other users have built custom logic that evaluates browser attributes before making policy or routing decisions. Each solves a unique problem that would otherwise require waiting for a vendor to build a specific, niche integration with a third-party system. Instead, customers are building exactly what they need, on their timeline, with logic they own.
A programmable platform that changes the conversation
We believe the future of enterprise security isn’t a monolithic platform that tries to do everything. It’s a composable and programmable platform that gives customers the tools and flexibility to extend it in any direction.
For security teams, we expect our platform to change the conversation. Instead of filing a feature request and hoping it makes the roadmap, you can build a tailored solution that addresses your exact requirements today.
For our partners and managed security service providers (MSSPs), our platform opens up their ability to build and deliver solutions for their specific customer base. That means industry-specific solutions, or capabilities for customers in a specific regulatory environment. Custom integrations become a competitive advantage, not a professional services engagement.
And for our customers, it means you’re building on a platform that is easy to deploy and fundamentally adaptable to your most complex and changing needs. Your security platform grows with you — it doesn’t constrain you.
What’s next
We’re just getting started. Throughout 2026, you’ll see us continue to deepen the integration between Cloudflare One and our Developer Platform. We plan to start by creating custom actions in Cloudflare Gateway that support dynamic policy enforcement. These actions can use auxiliary data stored in your organization’s existing databases without the administrative or compliance challenges of migrating that data into Cloudflare. These same custom actions will also support request augmentation to pass along Cloudflare attributes to your internal systems, for better logging and access decisions in your downstream systems.
In the meantime, the building blocks are already here. External evaluation rules, custom device posture checks, Gateway redirects, and the full power of Workers are available today. If you’re not sure where to start, our developer documentation has guides and reference architectures for extending Cloudflare One.
We built Cloudflare on the belief that security should be ridiculously easy to use, but we also know that “easy” doesn’t mean “one-size-fits-all.” It means giving you the tools to build exactly what you need. We believe that’s the future of SASE.
The 7.0-rc2 kernel prepatch is out for
testing. According to Linus:
So I’m not super-happy with how big this is, but I’m hoping it’s
just the random timing noise we see every once in a while where I
just happen to get more pull requests one week, only for the next
week to then be quieter.
Version 1.24.0 of the groff text-formatting system has been released.
Improvements include the ability to insert hyperlinks between man pages, a
new polygon command for the pic preprocessor, various
PDF-output improvements, and more.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.