Monday, January 19, 2026

Cloudflare Zero-Day Vulnerability Enables Any Host Access Bypassing Protections | Post by Cyber Security News



A critical zero-day vulnerability in Cloudflare's Web Application Firewall (WAF)allowed attackers to bypass security controls and directly access protected origin servers through a certificate validation path.

Security researchers from FearsOff discovered that requests targeting the /.well-known/acme-challenge/ directory could reach origins even when customer-configured WAF rules explicitly blocked all other traffic.

The Automatic Certificate Management Environment (ACME) protocol automates SSL/TLS certificate validation by requiring Certificate Authorities (CAs) to verify domain ownership.


Friday, January 16, 2026

Want to see an eclipse next year? Here’s where to go.




The biggest astronomical events of 2026, including solar and lunar eclipses, planet parades and the Artemis II mission to the moon.

By Andrea Sachs


https://www.washingtonpost.com/travel/2025/12/26/2026-solar-eclipse-viewing/