Sunday , March 16 2025
typist

Russia blocks thousands websites using Cloudflare’s privacy service

Russia’s media censor, Roskomnadzor, has blocked thousands of local websites using Cloudflare’s encryption feature that enhances online privacy and security.

Local media reports indicate that several websites were blocked overnight on October 6. These sites use Cloudflare’s Encrypted Client Hello (ECH) feature, which enhances user privacy by making it harder for third parties to track site visits.

Researcher found non protected database form ESHYFT containig 86000 records

Cybersecurity researcher Jeremiah Fowler found and reported a non-password-protected database with over 86,000 records belonging to ESHYFT, a New Jersey-based...
Read More
Researcher found non protected database form ESHYFT containig 86000 records

CVE-2024-55591 and CVE-2025-24472
New SuperBlack ransomware exploits Fortinet flaws

Forescout Research- Vedere Labs identified a series of intrusion based on two Fortinet vulnerabilities which began with the exploitation of...
Read More
CVE-2024-55591 and CVE-2025-24472  New SuperBlack ransomware exploits Fortinet flaws

CVE-2025-25291 & CVE-2025-25292
Attention! GitLab Patched Critical Authentication Bypass Flaws

GitLab has released versions 17.9.2, 17.8.5, and 17.7.7 for its Community and Enterprise Editions to fix security vulnerabilities, including a...
Read More
CVE-2025-25291 & CVE-2025-25292  Attention! GitLab Patched Critical Authentication Bypass Flaws

CVE-2025-20138
Cisco released High Security Alert for IOS XR Software

Cisco has issued a security advisory for a high-severity vulnerability in its IOS XR Software, labeled CVE-2025-20138, with a CVSS...
Read More
CVE-2025-20138  Cisco released High Security Alert for IOS XR Software

400+ IPs Exploiting Multiple SSRF Vulnerabilities

GreyNoise warns of a coordinated increase in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities across various platforms. "At least...
Read More
400+ IPs Exploiting Multiple SSRF Vulnerabilities

NVIDIA has released update for NVIDIA Riva

NVIDIA has released a software update for Riva to fix security vulnerabilities that could allow privilege escalation, data tampering, denial...
Read More
NVIDIA has released update for NVIDIA Riva

CVE-2025-24201
Apple fixes 0-day exploited in “extremely sophisticated attack”

On Tuesday, Apple fixed a critical zero-day vulnerability affecting nearly all supported iPhones and iPads. The company noted that it...
Read More
CVE-2025-24201  Apple fixes 0-day exploited in “extremely sophisticated attack”

Microsoft’s March 2025 updates fix 7 zero-day, 57 flaws

Microsoft's March 2025 Patch Tuesday update fixes 57 flaws, including seven zero-day exploits, six of which are actively being exploited....
Read More
Microsoft’s March 2025 updates fix 7 zero-day, 57 flaws

Ballista Botnet infects 6000 Unpatched TP-Link Routers

Cato CRTL team said, a new botnet campaign dubbed Ballista target the unpatched TP-Link Archer routers. CVE-2023-1389 is a serious...
Read More
Ballista Botnet infects 6000 Unpatched TP-Link Routers

CVE-2025-24813
Flaw in Apache Tomcat Exposes Servers to RCE

A critical vulnerability, CVE-2025-24813, has been found in Apache Tomcat, which could let attackers execute remote code, leak sensitive data,...
Read More
CVE-2025-24813  Flaw in Apache Tomcat Exposes Servers to RCE

On Thursday, Roskomnadzor advised Russian website owners to cease using Cloudflare’s CDN due to the company’s recent activation of the ECH extension by default.

“This technology is a way to bypass restrictions on access to information that’s banned in Russia. Using it goes against Russian law,” Roskomnadzor said.

The Russian internet regulator advised local website owners to use domestic CDN services, which help deliver web content faster and more efficiently.

“Domestic CDN services ensure reliable and secure operation of websites and protect them against cyberattacks,” Roskomnadzor said. The agency didn’t provide any details on the legal force of its “recommendation” or what would happen to companies that do not comply with it.

Russian censors are taking action to limit citizens’ access to information. Earlier this year, Roskomnadzor requested that Apple remove various VPN services from the Russian App Store, which helped users bypass government censorship.

The Russian government has blocked most Western social networks, news media, and local opposition outlets from being accessed via Russian IP addresses.

Cloudflare’s new restrictions will further reduce online information for Russian citizens. Meduza, an independent media outlet banned in Russia, reported that Cloudflare previously allowed local users to access its site and bypass restrictions. Now, users must seek alternative methods.

Russian experts estimate that Cloudflare holds about 44% of the CDN market, meaning that switching to alternatives will take time and incur extra costs.

When Russia invaded Ukraine, Cloudflare, unlike many other Western tech companies, did not terminate all its services inside the country. “Russia needs more internet access, not less,” the company said in a statement at the time.

“We’ve seen a dramatic increase in requests from Russian networks to worldwide media, reflecting a desire by ordinary Russian citizens to see world news beyond that provided within Russia,” Cloudflare added.

To comply with U.S. sanctions, the company ended services for customers associated with sanctions, including those connected to Russian financial institutions and influence operations.’

After the invasion, some Russian tech companies stopped using Cloudflare, as Russia considers the company “unfriendly.” However, others kept using it to protect their websites from increasing DDoS attacks, according to Russian experts.

Roskomnadzor announced that Russia has a national system to combat DDoS attacks, launched in March. It has reportedly assisted Russian organizations in thwarting over 10,000 attacks.

Russia seeks to isolate its internet and replace foreign technology with local options. However, this shift encounters challenges like high costs and a shortage of suitable domestic alternatives, as indicated by local tech experts in an interview last October.

Check Also

CYFIRMA

FinStealer Malware Targets Indian Bank’s Mobile Users, Stealing Credentials

CYFIRMA analysis reveals a sophisticated malware campaign that exploits a major Indian bank’s brand through …

Leave a Reply

Your email address will not be published. Required fields are marked *