phishing

2 posts

cloudflare

Celebrating 12 years of Project Galileo (opens in new tab)

Project Galileo, launched by Cloudflare 12 years ago, provides free cybersecurity services to more than 3,400 civil society websites across 120 countries. Its anniversary report shows that journalists, human rights groups, and nonprofits face more frequent and intense attacks than other Internet users, especially during politically sensitive work. Cloudflare is responding with expanded research, case studies, partnerships, and a call for accessible security protections. ## Project Galileo’s Mission and Reach - The program protects journalists, human rights defenders, and nonprofit organizations from being forced offline. - It now supports more than 3,400 websites in 120 countries. - Cloudflare’s global network spans more than 335 cities in 125 countries, with over 20% of the web behind its infrastructure. ## Cyberattacks Targeting Civil Society Cloudflare’s first comprehensive annual report compares threats against civil society with attacks against Internet users more broadly. - DDoS attacks were the most common threat, often lasting for days or weeks. - Civil society organizations faced website vulnerability exploitation attempts at more than seven times the rate of other Cloudflare customers. - Media organizations were especially affected. - Journalists working in exile received nearly four times more malicious traffic than journalism organizations overall. - Almost 10% of emails processed for civil society organizations contained potential phishing material. - Attacks often coincided with investigative reporting, public advocacy, or other critical organizational activities. Cloudflare calls for affordable cybersecurity, greater transparency around cyberattacks and Internet shutdowns, and default integration of AI-aware and post-quantum protections. The company plans to publish the report annually to track changing threat patterns. ## Case Studies of Project Galileo Participants Sixteen case studies illustrate the varied security needs of participating organizations, including: - Digital rights groups such as SHARE Foundation. - Investigative and independent media organizations, including OCCRP, elTOQUE, and China Digital Times. - Organizations documenting conflict and human rights abuses, such as Ukraine War Archive. - Research and public-interest institutions including Our World in Data and the Bulletin of Atomic Scientists. - Environmental, legal, scientific, and humanitarian groups such as Sea Shepherd Brazil, Activist Rights, and the Royal Meteorological Society. ## Expanding the Partner Network Project Galileo depends on 59 civil society partners that review and approve applications. - Partners contribute local expertise and help identify organizations that need protection. - Previous collaborations produced initiatives such as email security with Protect.ngo and Internet measurement work through UNICEF’s Giga project. - Cloudflare has focused on expanding access beyond North America and Europe through regional events and partnerships. - Recent Asia-Pacific partners include EngageMedia and the OpenCulture Foundation. - The anniversary announcement introduces three additional partners serving journalists, including the International Center for Journalists and Media Cluster Norway. Project Galileo’s next phase combines threat intelligence, direct protection, regional partnerships, and specialized services for journalism organizations. Its broader recommendation is that reliable cybersecurity should be treated as essential infrastructure for civil society and public discourse.

figma

Our approach to security at speed | Figma Blog (opens in new tab)

Figma’s security team aims to help teams ship quickly without compromising safety. Its approach combines early risk assessment, reusable technical controls, decentralized decision-making, and transparent collaboration rather than rigid mandates. The goal is to make security an enabler of product development. ## Systematically Assessing Risk - Security reviews upcoming features and workflows to identify risks early. - Teams use a three-question “ThreatJam” survey before security office hours, held three times weekly. - For FigJam’s rich link previews, the team identified risks including: - **SSRF**, where attackers could request internal Figma resources. - **Denial-of-service attacks** against linked websites. - Malicious HTML that could deface or execute code within FigJam. - Figma isolated link scraping and parsing in a cloud function running on a separate virtual machine and network. - Additional protections included: - Cloud-function rate limiting. - Temporary storage of scraped data. - Restricting requests to standard HTTP and HTTPS ports. - Limiting parsed HTML to approved tags. - Reusing existing plugin and widget security mechanisms. ## Reusable and Decentralized Security Solutions - Security provides customized guidance while avoiding centralized approval processes. - The team builds reusable libraries, frameworks, documentation, and security patterns. - Solutions developed for one product can serve as case studies for other engineering teams. - Office-hours notes are shared across Figma so teams can understand security reasoning and apply it independently. - This model allows security practices to scale as the company grows. ## Defending Against Phishing and Information Disclosure - Figma uses technical controls to protect employees, devices, and internal data. - Access to internal sites requires a passwordless second factor scoped to the specific site. - New employees receive hardware authenticator keys. - Employees are also encouraged to register biometric authenticators such as Touch ID or Windows Hello. Figma’s model demonstrates that security can move at development speed when teams assess threats early, isolate risky functionality, automate defenses, and share solutions broadly. Companies seeking a similar approach should prioritize reusable controls and security collaboration over process-heavy gates.