360SOFTY

Insights

Engineering Insights

Practical writing on software architecture, SaaS products, AI automation, legacy modernisation, and the business of building reliable systems.

RSS

Curated links from external sources — not 360Softy original articles.

ExternalFrontend Development
Vercel Blog

CVE-2025-48068

A low-severity vulnerability in the Next.js dev server has been addressed. This vulnerability affects Next.js versions through and through . It includes two related issues affecting the local development server: and . Both stem from the lack of origin validation on development server resources.13.0.014.2.2915.0.015.2.1Cross-Site WebSocket Hijacking (CSWSH)Cross-Origin Script Inclusion When running , a malicious website can:next dev The root cause is insufficient origin verification on local

Vercel BlogRead original
ExternalCloud
Cloudflare Changelog

Browser Run - Playwright MCP server is now compatible with Browser Rendering

We're excited to share that you can now use the Playwright MCP server with Browser Rendering. Once you deploy the server, you can use any MCP client with it to interact with Browser Rendering. This allows you to run AI models that can automate browser tasks, such as taking screenshots, filling out forms, or scraping data. Playwright MCP is available as an npm package at @cloudflare/playwright-mcp. To install it, type: npm i -D @cloudflare/playwright-mcp yarn add -D @cloudflar

Browser Run
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

WAF - Updated attack score model

We have deployed an updated attack score model focused on enhancing the detection of multiple false positives (FPs). As a result of this improvement, some changes in observed attack scores are expected.

WAF
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

SSL/TLS, Cloudflare for SaaS, Secrets Store - Increased limits for Cloudflare for SaaS and Secrets Store free and Pay-as-you-go plans

With upgraded limits to all free and paid plans, you can now scale more easily with Cloudflare for SaaS and Secrets Store. Cloudflare for SaaS allows you to extend the benefits of Cloudflare to your customers via their own custom or vanity domains. Now, the limit for custom hostnames on a Cloudflare for SaaS Pay-as-you-go plan has been raised from 5,000 custom hostnames to 50,000 custom hostnames. With custom origin server -- previously an enterprise-only feature -- you can route traffic from on

SSL/TLSCloudflare for SaaSSecrets Store
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Gateway - Gateway Protocol Detection Now Available for Pay-as-you-go and Free Plans

All Cloudflare One Gateway users can now use Protocol detection logging and filtering, including those on Pay-as-you-go and Free plans. With Protocol Detection, admins can identify and enforce policies on traffic proxied through Gateway based on the underlying network protocol (for example, HTTP, TLS, or SSH), enabling more granular traffic control and security visibility no matter your plan tier. This feature is available to enable in your account network settings for all accounts. For more inf

Gateway
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

Gateway - Gateway Protocol Detection Now Available for Pay-as-you-go and Free Plans

All Cloudflare One Gateway users can now use Protocol detection logging and filtering, including those on Pay-as-you-go and Free plans. With Protocol Detection, admins can identify and enforce policies on traffic proxied through Gateway based on the underlying network protocol (for example, HTTP, TLS, or SSH), enabling more granular traffic control and security visibility no matter your plan tier. This feature is available to enable in your account network settings for all accounts. For more inf

Gateway
Cloudflare ChangelogRead original
ExternalCloud
Cloudflare Changelog

WAF - WAF Release - 2025-05-27

This week’s roundup covers nine vulnerabilities, including six critical RCEs and one dangerous file upload. Affected platforms span cloud services, CI/CD pipelines, CMSs, and enterprise backup systems. Several are now addressed by updated WAF managed rulesets. Key Findings Ingress-Nginx (CVE-2025-1098): Unauthenticated RCE via unsafe annotation handling. Impacts Kubernetes clusters. GitHub Actions (CVE-2025-30066): RCE through malicious workflow inputs. Targets CI/CD pipelines. Craft CMS (CVE-20

WAF
Cloudflare ChangelogRead original

Work with 360Softy

Building a SaaS product, AI system, or business platform?

Book a free consultation and we will tell you honestly whether we can help.