Rolled out to all points of presence on 14 May 2026. No action is required.
- New dashboard widget: challenged vs. dropped traffic by ASN.
- Added CVE-2026-1127 support to the rules engine.
- Proof-of-work challenge payload reduced by 28%.
- Security: updated TLS library to address Android WebView.
- Log streaming now supports OpenTelemetry.
- Reduced p99 filtering latency by 11% on HTTP/2 connections.
- Improved fingerprint consistency scoring for JA4 fingerprint matching clients.
- API: new endpoint challenged vs. dropped traffic by ASN.
Is the risk score exposed in the logs so we can build our own dashboards on it?
Is the risk score exposed in the logs so we can build our own dashboards on it?
Our auditors asked for exactly this kind of incident evidence under DORA.
Machine-readable ranges are at /ips.json and via the API.
How do you avoid challenging uptime monitors and partners?
Is the risk score exposed in the logs so we can build our own dashboards on it?
How do you avoid challenging uptime monitors and partners?
The point about origin IPs leaking through certificate transparency logs is underrated.
Solid runbook advice. The DNS-at-2am point hit home.
Great to hear, thanks for sharing your experience.