Category: IT|Feb 7, 2025 | Author: Admin

Cloudflare outage caused by botched blocking of phishing URL

Share on

An attempt to block a phishing URL in Cloudflare's R2 object storage platform backfired yesterday, triggering a widespread outage that brought down multiple services for nearly an hour.

Cloudflare outage caused by botched blocking of phishing URL

Cloudflare R2 is an object storage service similar to Amazon S3, designed for scalable, durable, and low-cost data storage. It offers cost-free data retrievals, S3 compatibility, data replication across multiple locations, and Cloudflare service integration.

 

The outage occurred yesterday when an employee responded to an abuse report about a phishing URL in Cloudflare's R2 platform. However, instead of blocking the specific endpoint, the employee mistakenly turned off the entire R2 Gateway service.

 

"During a routine abuse remediation, action was taken on a complaint that inadvertently disabled the R2 Gateway service instead of the specific endpoint/bucket associated with the report," explained Cloudflare in its post-mortem write-up.

 

"This was a failure of multiple system level controls (first and foremost) and operator training."

 

The incident lasted for 59 minutes, between 08:10 and 09:09 UTC, and apart from the R2 Object Storage itself, it also affected services such as:

 

  • Stream – 100% failure in video uploads and streaming delivery.

  • Images – 100% failure in image uploads/downloads.

  • Cache Reserve – 100% failure in operations, causing increased origin requests.

  • Vectorize – 75% failure in queries, 100% failure in insert, upsert, and delete operations.

  • Log Delivery – Delays and data loss: Up to 13.6% data loss for R2-related logs, up to 4.5% data loss for non-R2 delivery jobs.

  • Key Transparency Auditor – 100% failure in signature publishing & read operations.


There were also indirectly impacted services that experienced partial failures like Durable Objects, which had a 0.09% error rate increase due to reconnections after recovery, Cache Purge, which saw a 1.8% increase in errors (HTTP 5xx) and 10x latency spike, and Workers & Pages, that had a 0.002% deployment failures, affecting only projects with R2 bindings.

 

Cloudflare notes that both human error and the absence of safeguards such as validation checks for high-impact actions were key to this incident.

 

The internet giant has now implemented immediate fixes like removing the ability to turn off systems in the abuse review interface and restrictions in the Admin API to prevent service disablement in internal accounts.

 

Additional measures to be implemented in the future include improved account provisioning, stricter access control, and a two-party approval process for high-risk actions.

 

In November 2024, Cloudflare experienced another notable outage for 3.5 hours, resulting in the irreversible loss of 55% of all logs in the service.

 

That incident was caused by cascading failures in Cloudflare's automatic mitigation systems triggered by pushing a wrong configuration to a key component in the company's logging pipeline.

Sponsored Ads:

Comments:


Outlook-14-03-25.png

Microsoft says button to restore classic Outlook is broken

Category: Microsoft|Mar 14, 2025 | Author: Admin
GitLab-13-03-25.png

GitLab patches critical authentication bypass vulnerabilities

Category: IT|Mar 13, 2025 | Author: Admin
Firefox-12-03-25.png

Mozilla warns users to update Firefox before certificate expires

Category: Microsoft|Mar 12, 2025 | Author: Admin
Windows-headpic-11-03-25.png

Microsoft replacing Remote Desktop app with Windows App in May

Category: Microsoft|Mar 11, 2025 | Author: Admin
swiss-flag-10-03-25.png

Swiss critical sector faces new 24-hour cyberattack reporting rule

Category: IT|Mar 10, 2025 | Author: Admin
sound-waves-09-03-25.png

New Chirp tool uses audio tones to transfer data between devices

Category: IT|Mar 9, 2025 | Author: Admin
esp32-08-03-25.png

Undocumented "backdoor" found in Bluetooth chip used by a billion Devices

Category: IT|Mar 8, 2025 | Author: Admin
webcam-07-03-25.png

Ransomware gang encrypted network from a webcam to bypass EDR

Category: IT|Mar 7, 2025 | Author: Admin
Microsoft-365-06-03-25.png

Microsoft 365 apps will prompt users to back up files in OneDrive

Category: Microsoft|Mar 6, 2025 | Author: Admin
YouTube-05-03-25.png

YouTube warns of AI-generated video of its CEO used in phishing attacks

Category: Google|Mar 5, 2025 | Author: Admin
Microsoft_365-04-03-25.png

New Microsoft 365 outage impacts Teams, causes call failures

Category: Microsoft|Mar 4, 2025 | Author: Admin
UK-ICO-03-03-25.png

UK watchdog probes TikTok and Reddit over child privacy concerns

Category: IT|Mar 3, 2025 | Author: Admin
artificial-intelligence-eyes-02-03-25.png

Nearly 12,000 API keys and passwords found in AI training dataset

Category: IT|Mar 2, 2025 | Author: Admin
Android-01-03-25.png

Serbian police used Cellebrite zero-day hack to unlock Android phones

Category: Google|Mar 1, 2025 | Author: Admin
Skype-28-02-25.png

Microsoft confirms it's killing off Skype in May, after 14 years

Category: IT|Feb 28, 2025 | Author: Admin
more