Mastercard

2 posts

cloudflare3 min readCurated summary

Translating risk insights into actionable protection: leveling up security posture with Cloudflare and Mastercard

Organizations are expanding their Internet-facing assets faster than they can inventory and secure them, leaving shadow domains, forgotten hosts, and vulnerable services exposed. Cloudflare and Mastercard plan to integrate RiskRecon attack surface intelligence into Cloudflare Security Insights to continuously discover these risks and recommend remediation. The integration is intended to shift security from periodic audits toward ongoing visibility and protection. ## Attack Surface Intelligence - Mastercard RiskRecon maps an organization’s public Internet footprint using outside-in, publicly available data. - It can identify shadow IT, forgotten subdomains, unauthorized cloud servers, exposed services, weak authentication, outdated software, and encryption problems. - A 2025 study of 15,896 breached organizations found that major posture gaps made companies: - 5.3 times more likely to experience ransomware. - 3.6 times more likely to suffer a data breach. ## Combining Discovery with Cloudflare Protection - RiskRecon identifies security gaps, while Cloudflare provides controls to address them. - Discovered assets can be routed through Cloudflare’s proxy without changing the underlying application or website. - In a sample covering approximately 388,000 organizations and 18 million systems, Cloudflare-proxied systems showed: - 53% fewer software vulnerabilities. - 58% fewer SSL/TLS issues. - 98% fewer instances of malicious behavior. ## Finding Shadow Domains and Unprotected Hosts - Cloudflare Security Insights already detects issues for domains that are proxied through Cloudflare, including DNS errors, weak encryption, and inactive WAF rules. - The Mastercard integration will extend visibility to domains and hosts that Cloudflare does not yet know about or protect. - RiskRecon continuously profiles organizations’ Internet footprints and identifies associated domains, hosts, and software stacks. - Assets will receive criticality ratings: - **High:** Sensitive-data systems, authenticated applications, databases, or remote-access services. - **Medium:** Brochure sites adjacent to high-criticality systems. - **Low:** Brochure sites with no proximity to critical systems. ## Turning Findings into Remediation - Security Insights is designed to recommend concrete fixes rather than only report vulnerabilities. - Suggested actions may include: - Enabling the Cloudflare proxy for discovered zones and hosts. - Activating WAF, DDoS, and bot protection. - Enforcing stronger TLS settings. - Applying controls such as API Shield or specific WAF rules. - Future plans include risk scoring and AI-assisted diagnosis that correlates findings with traffic and recommends targeted configurations. ## Availability - The planned integration is expected to enter preview in the third quarter of 2026 for Information Security practitioners on pay-as-you-go and Enterprise accounts. The partnership’s practical goal is to help organizations discover assets they did not know existed, prioritize the most dangerous exposures, and protect them through Cloudflare before attackers exploit them.

Read original(opens in new tab)
stripe2 min readCurated summary

Supporting additional payment methods for agentic commerce

Stripe is expanding Shared Payment Tokens (SPTs) to support more payment methods for agentic commerce. SPTs now cover Mastercard Agent Pay, Visa Intelligent Commerce, and BNPL options from Affirm and Klarna, allowing AI agents to make authorized purchases without accessing customers’ underlying payment credentials. Stripe says this makes it the first provider to combine agentic network and BNPL tokens through one payment primitive. ## Expanded Support for Agentic Payments - Sellers interact only with SPTs; Stripe provisions and manages the underlying payment tokens. - Businesses already processing payments through Stripe automatically gain access to these methods in agentic transactions. - The new capabilities are already being used to process payments across supported AI agents. ## Network-Led Payments from Mastercard and Visa - Mastercard and Visa issue secure agentic network tokens that let authorized AI agents initiate payments on a customer’s behalf. - Stripe provisions a token based on the customer’s purchase intent and shares it with the agent. - Agents can reuse the token across participating sellers and locations where Mastercard or Visa are accepted. - Payment networks translate the token to the latest underlying card number, verify and authorize transactions, and support fraud and dispute management. - Additional authorization data helps issuers make better provisioning and transaction decisions. ## Affirm and Klarna for Agentic Commerce - Stripe is adding SPT support for Affirm and Klarna, enabling agents to offer installment payment options. - BNPL transactions now exceed $300 billion globally, and Stripe reports up to a 14% revenue increase in BNPL-eligible sessions. - When a customer chooses BNPL, Stripe displays the provider’s confirmation flow in the agent interface and securely passes seller credentials to the provider. - The customer experience remains familiar while Stripe handles the integration details. Stripe plans to add more payment methods to SPTs, broadening the range of payment options available to customers and AI agents.

Read original(opens in new tab)