// CloudflareHIGH
Cloudflare published research on August 19, 2026 demonstrating a Spectre-class side-channel attack against Cloudflare Workers capable of stealing JWT authentication tokens at 12 bits per second—360 times faster than prior techniques. The attack exploits speculative execution in V8 JavaScript engine and uses WebSocket keep-alive messages within Durable Objects to evade behavioral detection. Cloudflare confirmed no evidence of real-world exploitation and stated that three layers of mitigation are already deployed across production infrastructure.
// Get alerts for Cloudflare