Rolled out to all points of presence on 2 August 2026. No action is required.
- Security: updated TLS library to address JA4 fingerprint matching.
- Reduced p99 filtering latency by 25% on HTTP/2 connections.
- API: new endpoint per-tenant rate limits.
- Fixed a race in origin health checks that could mark a healthy origin as down for up to 27 seconds.
Solid runbook advice. The DNS-at-2am point hit home.
Our auditors asked for exactly this kind of incident evidence under DORA.
Nice to read a vendor blog that admits what went wrong.
Carpet bombing is nasty. Good to see a clear explanation of it.
The point about origin IPs leaking through certificate transparency logs is underrated.