Network Security

Faulty Phishing Site Blocking Disrupts Cloudflare Services

Exterior view of Cloudflare headquarters in San Francisco.

BleepingComputer reports that Cloudflare had its Stream, Images, Cache Reserve, Vectorize, Log Delivery, and Key Transparency Auditor services significantly interrupted for almost an hour on Thursday due to the mishandled thwarting of a phishing link in the IT service management firm's R2 object storage platform.

Also partially impacted by the incident — which involved the accidental takedown of the whole R2 Gateway service instead of the targeted endpoint alone — were Cloudflare's Cache Purge, Durable Objects, and Workers & Pages services.

"During a routine abuse remediation, action was taken on a complaint that inadvertently disabled the R2 Gateway service instead of the specific endpoint/bucket associated with the report," said Cloudflare. "This was a failure of multiple system level controls (first and foremost) and operator training."

Despite already moving to curb service deactivation by removing such a capability from the Admin API's abuse review interface, Cloudflare is also mulling to bolster account provisioning and access controls.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

You can skip this ad in 5 seconds

Cookies

This website uses cookies to improve your experience, provide social media features and deliver advertising offers that are relevant to you.

If you continue without changing your settings, you consent to our use of cookies in accordance with our privacy policy. You may disable cookies.