george yoxall
Security.
Edge.
AI.
SWE @ Cloudflare
appsec · workers · ai
20+
vulns reported
8+
acknowledged by
Google · Microsoft
Cloudflare + more
2015
security research
attacks blocked
cloudflare network

Senior software engineer at Cloudflare, working on application security and AI at the network edge. I've been reporting vulnerabilities since 2015 — acknowledged by Google, Microsoft, Cloudflare, and others. I build things on Workers and write about what I find and build.

currently @ cloudflare.com
writing
Turning Cloudflare's threat indicators into real-time WAF rules
How Cloudforce One threat intelligence feeds directly into the WAF — blocking high-risk traffic from specific threat actors and targeted industries in real time.
blog.cloudflare.com ↗
How Cloudflare's client-side security made the npm supply chain attack a non-event
A recent npm supply chain attack compromised 18 popular packages. How Cloudflare's graph-based ML model, analysing 3.5 billion scripts daily, detected and blocked it automatically.
blog.cloudflare.com ↗
Stopping SharePoint's CVE-2019-0604
A critical SharePoint vulnerability actively exploited by APTs in the wild — how Cloudflare's WAF responded.
blog.cloudflare.com ↗
Microsoft Office XSS
Stored cross-site scripting (XSS) via the email subject field in office.com — 9 months responsible disclosure, Hall of Fame Jan 2018.
this site
HSTS preloading
The first-request problem and why I enrolled my site on the strict HSTS preload list.
this site
Amazon XSS
Reflected cross-site scripting (XSS) across all Amazon locales via the storeZip parameter. Reported and patched in 2 weeks.
this site