<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WAF Rules &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/waf-rules/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 07 Mar 2024 14:00:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>General availability for WAF Content Scanning for file malware protection</title>
		<link>https://noise.getoto.net/2024/03/07/general-availability-for-waf-content-scanning-for-file-malware-protection/</link>
		
		<dc:creator><![CDATA[Radwa Radwan]]></dc:creator>
		<pubDate>Thu, 07 Mar 2024 14:00:14 +0000</pubDate>
				<category><![CDATA[Anti Malware]]></category>
		<category><![CDATA[Content Scanning]]></category>
		<category><![CDATA[General Availability]]></category>
		<category><![CDATA[Product News]]></category>
		<category><![CDATA[Security Week]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=17e71adc4efffbc46917496cd83c1209</guid>

					<description><![CDATA[Announcing the General Availability of WAF Content Scanning, protecting your web applications and APIs from malware by scanning files in-transit]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>How Cloudflare’s AI WAF proactively detected the Ivanti Connect Secure critical zero-day vulnerability</title>
		<link>https://noise.getoto.net/2024/01/23/how-cloudflares-ai-waf-proactively-detected-the-ivanti-connect-secure-critical-zero-day-vulnerability/</link>
		
		<dc:creator><![CDATA[Himanshu Anand http://blog.cloudflare.com/author/himanshu/]]></dc:creator>
		<pubDate>Tue, 23 Jan 2024 14:00:48 +0000</pubDate>
				<category><![CDATA[AI WAF]]></category>
		<category><![CDATA[Ivanti Connect Secure]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[WAF Attack Score]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<category><![CDATA[Zero Day Threats]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=df842da45900af2f1145f5384d2f03e0</guid>

					<description><![CDATA[The issuance of Emergency Rules by Cloudflare on January 17, 2024, helped give customers a big advantage in dealing with these threats]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Protection against CVE-2021-45046, the additional Log4j RCE vulnerability</title>
		<link>https://noise.getoto.net/2021/12/15/protection-against-cve-2021-45046-the-additional-log4j-rce-vulnerability/</link>
		
		<dc:creator><![CDATA[Gabriel Gabor]]></dc:creator>
		<pubDate>Wed, 15 Dec 2021 13:56:13 +0000</pubDate>
				<category><![CDATA[log4j]]></category>
		<category><![CDATA[log4shell]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6576ebcbd20cf31a2c62b02e1f043027</guid>

					<description><![CDATA[This vulnerability is actively being exploited and anyone using Log4J should update to version 2.16.0 as soon as possible, even if you have previously updated to 2.15.0. The latest version can be found on the Log4J download page.]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2021/12/image1-81.png" length="0" type="" />

			</item>
		<item>
		<title>Inside the log4j2 vulnerability (CVE-2021-44228)</title>
		<link>https://noise.getoto.net/2021/12/10/inside-the-log4j2-vulnerability-cve-2021-44228/</link>
		
		<dc:creator><![CDATA[John Graham-Cumming]]></dc:creator>
		<pubDate>Fri, 10 Dec 2021 18:36:10 +0000</pubDate>
				<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<category><![CDATA[Zero Day Threats]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=28c48dc0da0fee469d03f1d07559f964</guid>

					<description><![CDATA[In this post we explain the history of this vulnerability, how it was introduced, how Cloudflare is protecting our clients. We will update later with actual attempted exploitation we are seeing blocked by our firewall service.]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2021/12/Inside-the-log4j2-vulnerability--CVE-2021-44228--OG.png" length="0" type="" />

			</item>
		<item>
		<title>CVE-2021-44228 &#8211; Log4j RCE 0-day mitigation</title>
		<link>https://noise.getoto.net/2021/12/10/cve-2021-44228-log4j-rce-0-day-mitigation/</link>
		
		<dc:creator><![CDATA[Gabriel Gabor]]></dc:creator>
		<pubDate>Fri, 10 Dec 2021 11:39:08 +0000</pubDate>
				<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<category><![CDATA[Zero Day Threats]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=06ce6a811172706c38a75913740ecb4b</guid>

					<description><![CDATA[A zero-day exploit affecting the popular Apache Log4j utility (CVE-2021-44228) was made public on December 9, 2021 that results in remote code execution (RCE).
This vulnerability is actively being exploited and anyone using Log4j should update to version 2.15.0 as soon as possible.]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2021/12/image1-53.png" length="0" type="" />

			</item>
		<item>
		<title>Get notified when your site is under attack</title>
		<link>https://noise.getoto.net/2021/12/03/get-notified-when-your-site-is-under-attack/</link>
		
		<dc:creator><![CDATA[Michael Tremante]]></dc:creator>
		<pubDate>Fri, 03 Dec 2021 13:59:21 +0000</pubDate>
				<category><![CDATA[notifications]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5d1c8e218b485ae4cc99ba00480a6566</guid>

					<description><![CDATA[Cloudflare can now send proactive notifications about any application security event spike, so you are warned whenever an attack might be targeting your application.]]></description>
		
		
		<enclosure url="http://blog.cloudflare.com/content/images/2021/12/image2-2.png" length="0" type="" />

			</item>
		<item>
		<title>Helping Apache Servers stay safe from zero-day path traversal attacks (CVE-2021-41773)</title>
		<link>https://noise.getoto.net/2021/10/08/helping-apache-servers-stay-safe-from-zero-day-path-traversal-attacks-cve-2021-41773/</link>
		
		<dc:creator><![CDATA[Michael Tremante]]></dc:creator>
		<pubDate>Fri, 08 Oct 2021 10:29:26 +0000</pubDate>
				<category><![CDATA[Cloudflare Access]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=e16dfeb63242dcf959258d50832e0b69</guid>

					<description><![CDATA[On September 29th 2021, the Apache Security team was alerted of a path traversal vulnerability being actively exploited (zero-day) against Apache HTTP Server version 2.4.49. Customers running the affected Apache version, should update to 2.5.51 as soon as possible.]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2021/10/Helping-Apache-Servers-stay-safe-from-zero-day-path-traversal-attacks-header.png" length="0" type="" />

			</item>
		<item>
		<title>How Cloudflare helped mitigate the Atlassian Confluence OGNL vulnerability before the PoC was released</title>
		<link>https://noise.getoto.net/2021/09/08/how-cloudflare-helped-mitigate-the-atlassian-confluence-ognl-vulnerability-before-the-poc-was-released/</link>
		
		<dc:creator><![CDATA[Michael Tremante]]></dc:creator>
		<pubDate>Wed, 08 Sep 2021 09:18:01 +0000</pubDate>
				<category><![CDATA[Cloudflare Access]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=60bb56d6840811238f55ae4028355e37</guid>

					<description><![CDATA[On August 25, 2021, Atlassian released a security advisory affecting their Confluence application. The Cloudflare WAF soon after started mitigating an increase in malicious traffic to vulnerable endpoints ensuring customers remained protected.]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2021/09/image2-3.png" length="0" type="" />

			</item>
		<item>
		<title>Account Takeover Protection and WAF mitigations to help stop Global Brute Force Campaigns</title>
		<link>https://noise.getoto.net/2021/07/01/account-takeover-protection-and-waf-mitigations-to-help-stop-global-brute-force-campaigns/</link>
		
		<dc:creator><![CDATA[Michael Tremante]]></dc:creator>
		<pubDate>Thu, 01 Jul 2021 17:53:20 +0000</pubDate>
				<category><![CDATA[Exposed Credentials]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=22f71fafa25857ef5d33f7cf3c98d9d4</guid>

					<description><![CDATA[Today, we are making our Account Takeover Protection capabilities available to all paid plans at no additional charge.]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2021/07/image1-1.png" length="0" type="" />

			</item>
		<item>
		<title>Protecting against recently disclosed Microsoft Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065</title>
		<link>https://noise.getoto.net/2021/03/07/protecting-against-recently-disclosed-microsoft-exchange-server-vulnerabilities-cve-2021-26855-cve-2021-26857-cve-2021-26858-and-cve-2021-27065/</link>
		
		<dc:creator><![CDATA[Patrick R. Donahue]]></dc:creator>
		<pubDate>Sun, 07 Mar 2021 00:47:20 +0000</pubDate>
				<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=0514d62506ff73290268c3243c813436</guid>

					<description><![CDATA[Cloudflare has deployed managed rules protecting customers against a series of remotely exploitable vulnerabilities that were recently found in Microsoft Exchange Server.]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2021/03/Screen-Shot-2021-03-06-at-4.43.00-PM.png" length="0" type="" />

			</item>
		<item>
		<title>Using HPKE to Encrypt Request Payloads</title>
		<link>https://noise.getoto.net/2021/02/19/using-hpke-to-encrypt-request-payloads/</link>
		
		<dc:creator><![CDATA[Miguel de Moura]]></dc:creator>
		<pubDate>Fri, 19 Feb 2021 12:00:00 +0000</pubDate>
				<category><![CDATA[crypto]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=efc55f95690bffaf537666483d9519b1</guid>

					<description><![CDATA[Allowing users to securely log parts of the request that match firewall rules while making it impossible for anyone else to decrypt.]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2021/02/Hybrid-WAF-keys-1.png" length="0" type="" />

			</item>
		<item>
		<title>Encrypting your WAF Payloads with Hybrid Public Key Encryption (HPKE)</title>
		<link>https://noise.getoto.net/2020/12/11/encrypting-your-waf-payloads-with-hybrid-public-key-encryption-hpke/</link>
		
		<dc:creator><![CDATA[Michael Tremante]]></dc:creator>
		<pubDate>Fri, 11 Dec 2020 15:00:00 +0000</pubDate>
				<category><![CDATA[firewall]]></category>
		<category><![CDATA[Privacy Week]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[WAF Rules]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=05f87830ed60e1e7d70603c21ee73967</guid>

					<description><![CDATA[Allowing logging for payloads that trigger the Web Application Firewall has always led to end-user privacy concerns. We built encrypted matched payload logging to solve this!]]></description>
		
		
		<enclosure url="https://blog.cloudflare.com/content/images/2020/12/image3-40.png" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 38/227 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-07 06:33:11 by W3 Total Cache
-->