Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•••
Sichere ProgrammierungDurable AI Agents: Workflow Strategies for Resilient Systems(29.09.2026 um 07:29 Uhr)
•
Sichere ProgrammierungWhat If Your AI Agent Never Had to Leave the Browser?(29.09.2026 um 07:30 Uhr)
•
AI & KI NachrichtenYour Agent Has 200 Tools. How Many Can It Abuse?(29.09.2026 um 07:32 Uhr)
•
Sichere ProgrammierungHow Relay Uses Memory to Stop Repeating Failed Support Steps(29.09.2026 um 07:35 Uhr)
•
Sichere Programmierung"Why My Agent Needed Hindsight Beyond Chat History ?"(29.09.2026 um 07:35 Uhr)
•
AI & KI NachrichtenBuilding an AI Customer Support Agent with Memory(29.09.2026 um 07:36 Uhr)
•
Sichere ProgrammierungVARdict - uphold or overturn a VAR room's decision(29.09.2026 um 07:38 Uhr)
••••
Sichere ProgrammierungDurable AI Agents: Workflow Strategies for Resilient Systems(29.09.2026 um 07:29 Uhr)
•
Sichere ProgrammierungWhat If Your AI Agent Never Had to Leave the Browser?(29.09.2026 um 07:30 Uhr)
•
AI & KI NachrichtenYour Agent Has 200 Tools. How Many Can It Abuse?(29.09.2026 um 07:32 Uhr)
•
Sichere ProgrammierungHow Relay Uses Memory to Stop Repeating Failed Support Steps(29.09.2026 um 07:35 Uhr)
•
Sichere Programmierung"Why My Agent Needed Hindsight Beyond Chat History ?"(29.09.2026 um 07:35 Uhr)
•
AI & KI NachrichtenBuilding an AI Customer Support Agent with Memory(29.09.2026 um 07:36 Uhr)
•
Sichere ProgrammierungVARdict - uphold or overturn a VAR room's decision(29.09.2026 um 07:38 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

How Migros Online protects its assets with Cloudflare - a DDoS Story

Nowadays, attackers are more and more eager to get your website down, to gather your data, to exploit every little vulnerability you might have. It has become a major concern for every company to protect itself against any malicious…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Nowadays, attackers are more and more eager to get your website down, to gather your data, to exploit every little vulnerability you might have. It has become a major concern for every company to protect itself against any malicious activity.



When thinking about what to put in place to improve your security, you have mainly two situations:




  • You're big enough and have the knowledge in-house to manage the whole security stack

  • You don't have the expertise or you don't want to spend a huge human effort on setting up the security



In the first case, you need to have one or multiple teams dedicated to the security to build a safe and secure infrastructure and to keep it up to date with the latest vulnerabilities found. Knowing that you should ask yourself "when" and not "if" you're going to be attacked, this team should also know how to react when something goes south at each security level.



For small companies or companies that don't want to invest in a highly-skilled security team, you will probably search for market solutions and providers that are able to handle these concerns for you, or at least that are going to ease the management of many security aspects. Nevertheless, it won’t prevent you from having security dedicated people to manage the selected solutions as well as other security aspects, like people awareness to prevent phishing for example.



Beware that choosing a third party comes with its downsides: you become, at a certain level, dependent of their infrastructure, their partners and their problems (availability, security). Thus, you can encounter issues over which you have no control.






Migros Online and Cloudflare



At Migros Online, we decided a few years back to work with Cloudflare to have a unique entrypoint for our infrastructure (on-premises back then, in the cloud today).



Using such a tool brought us many security and performance aspects for our website and our mobile applications:





  • Content Delivery Network (CDN): edge caching allows us to serve assets without hitting the backend on every requests


  • Web Application Firewall (WAF): we are able to protect our public endpoints with simple rules in a few clicks (or a few Terraform line of code ;-))


  • Basic sets of rules that are managed by Cloudflare directly allowing us to fix deeper issues with serenity (as an example, the log4Shell vulnerability was automatically handled by Cloudflare, giving us the time to patch our backend systems without pressure)


  • Bot protection: automatic categorization of the traffic and possibility to easily act on requests based on the rating done by the platform


  • Distributed Denial of Service (DDoS) protection: automatic discovery of DDoS attacks and direct mitigation


  • Zero Trust mechanisms: we are able to expose private endpoints, but secure them behind the Zero Trust product, bound with our authentication provider


  • Cloudflare Warp: a tunneling solution to access internal resources that we don't want to expose publicly, even behind Zero Trust



Thanks to Cloudflare, we were able to consolidate our public exposure, simplify its management and get confidence that we are in good hands when problems arise.






Cloudflare Immerse 2025



As an example of Cloudflare's usage for Migros Online, I went on stage (for the first time!) during the Cloudflare Immerse 2025 event in Zurich to present how Cloudflare helped us in mitigating DDoS attacks we faced in the past.



The recording is available below and outlines the Migros Online context, what issues we faced and how Cloudflare was a key element in solving the problem.





2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
2 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten How Migros Online protects its assets with Cloudflare - a DDoS Story

Thematisch verwandte Begriffe: Migros, Online, protects, assets · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-102367 | mall4j through 4.0 contains an insufficient session expiration vulnerab…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag