Rolled out to all points of presence on 29 August 2026. No action is required.
- Faster rule propagation: median 13 seconds to all PoPs.
- Log streaming now supports JA4 fingerprint matching.
- Fixed a race in origin health checks that could mark a healthy origin as down for up to 28 seconds.
- Improved fingerprint consistency scoring for /v1/incidents/{id}/export clients.
- Reduced p99 filtering latency by 6% on HTTP/2 connections.
- Deprecated OpenTelemetry; removal scheduled for the next major release.
- Managed WAF: 30 new signatures for recently disclosed CVEs.
Clear and practical, thanks.
Great write-up. We saw almost the same pattern on our login endpoint last month.
Solid runbook advice. The DNS-at-2am point hit home.
The point about origin IPs leaking through certificate transparency logs is underrated.
Clear and practical, thanks.
Nice to read a vendor blog that admits what went wrong.
Do you publish the edge IP ranges in a machine-readable format?
Could you share the dataset behind the percentages?
Carpet bombing is nasty. Good to see a clear explanation of it.
Thanks! Yes — the risk score and its components are included in every log record.