Things I build, break, fix, and write about

28 September 2026
Removed SSRF beta detections in Cloudflare WAF

Cloudflare WAF Managed Rules have a habit of changing underneath you, and old SSRF names can linger long after the protection has gone. I prefer to check the live block logs, then test the ugly request shapes my applications actually accept, because that is where gaps tend to hide.

28 September 2026
Weekly Tech Digest | 28 Sep 2026

Stay updated with the latest in tech! This digest covers AI ethics, auto industry shifts, and the impact of politics on technology, exploring today's...

27 September 2026
Cloudflare WAF metadata changes for WordPress XSS

Cloudflare WAF WordPress XSS detection now has a cleaner CVE label, but the behaviour has not changed; the rule still blocks the same traffic, just...

27 September 2026
Cloudflare Turnstile needs backend siteverify checks

Cloudflare Turnstile siteverify is the bit that matters, not the widget on the page. I have seen too many setups that look protected until you replay...

Latest blog posts you might like

28 September 2026
Removed SSRF beta detections in Cloudflare WAF

Cloudflare WAF Managed Rules have a habit of changing underneath you, and old SSRF names can linger long after the protection has gone. I prefer to check the live block logs, then test the ugly...

28 September 2026
Weekly Tech Digest | 28 Sep 2026

Stay updated with the latest in tech! This digest covers AI ethics, auto industry shifts, and the impact of politics on technology, exploring today's pressing issues.

27 September 2026
Cloudflare WAF metadata changes for WordPress XSS

Cloudflare WAF WordPress XSS detection now has a cleaner CVE label, but the behaviour has not changed; the rule still blocks the same traffic, just with less guesswork when I am reading logs. The...

27 September 2026
Cloudflare Turnstile needs backend siteverify checks

Cloudflare Turnstile siteverify is the bit that matters, not the widget on the page. I have seen too many setups that look protected until you replay the same token and watch the backend wave it...

26 September 2026
Cloudflare WAF scheduled release: log-only SQLi change

Cloudflare WAF scheduled release is one of those updates I trust less when it sounds tidy. Log-only first is sensible, because a fresh SQLi signature can look convincing right up until it starts...

26 September 2026
Log to Block for vBulletin exploit traffic

Cloudflare’s shift from log-only to blocking for vBulletin exploit traffic is the sort of change I prefer, boring and effective. Cloudflare WAF vBulletin RCE detection now does something useful by...

25 September 2026
Set maxRetransmits on Cloudflare Realtime SFU DataChannels

Cloudflare Realtime SFU DataChannels are easy to get half right, which is usually how I end up debugging them at midnight. Set `maxRetransmits` deliberately, because ordered delivery and retry budgets...

24 September 2026
TLS decryption for Cloudflare Gateway package registry

Cloudflare Gateway package registry security only becomes useful once TLS is decrypted, because the package name, version, and namespace live inside the request, not on the outside. I prefer to test...

24 September 2026
Set Cloudflare Artifacts EU data residency in API

Cloudflare Artifacts jurisdictions are fixed at namespace creation, so the choice is made once and lived with. I prefer that sort of bluntness, because if you get the API payload wrong, the only fix...

23 September 2026
Private by default for workers.dev URLs

Cloudflare Access for Workers finally fixes a mess I have tripped over more than once, where protection lived beside the Worker and drifted the moment a route or workers.dev URL changed. The new model...