Network Transparency
Last updated: 2026-09-05

Network changelog.

What's been happening across the CyberAdX network — delivery updates, incidents and how we resolved them, and improvements to how ads serve. Plain language, no spin. For live numbers, see the network stats →

Improvement

Ten publications, one standard: a network-wide search and AI-answer optimisation pass ahead of the next core update

Google shipped two core updates this year (March and May) and three spam updates (March, June and August). Each one rewards the same things: pages that load fast, say plainly what they are, carry no migration debris, and give search engines and AI answer engines something concrete to extract. Over 4 and 5 September we brought all ten publications on the network, 4,456 articles, up to one shared standard rather than waiting to see which site the next update would single out.

  • Improvement: Every site now publishes the same crawler policy, and it matches what our ai.txt files already promised. Search and answer agents (Google, Bing, OpenAI search, Perplexity, Claude search, Apple, Amazon, DuckDuckGo) are welcome. Model-training crawlers are not. Eight of the ten sites had a robots.txt that quietly contradicted this until now.

  • Fix: Images were the biggest technical debt. Hundreds of feature images were still loading from a third-party photo service, thousands were oversized PNGs, and none were cached at the edge. Every hero on every site is now stored locally as WebP with explicit dimensions and a one-year cache. Two of the smaller sites went from roughly 180 MB of images to under 35 MB.

  • Improvement: Search titles and descriptions: headlines are written for readers, and most ran well past the 70 characters a result snippet shows. Every long headline now has a dedicated search title, and every article has a real description instead of a body-text fallback. Across the network that was several thousand titles and descriptions.

  • Improvement: Tags were a mess left over from the Ghost era, with thousands of one-off terms, spelling variants and placeholders. Each site now uses a controlled vocabulary, every article was re-tagged against it, and a topic page exists only where there is real depth. One site went from 1,034 tags to about 210.

  • Fix: Migration residue in the articles themselves: link cards that had turned into raw blobs, bulleted lists glued onto a single line (over 17,000 items across four sites), duplicate headings and stale internal links. All repaired by script and checked.

  • Improvement: Key facts on news articles. Incident, enforcement and vulnerability stories now open with a short, extract-only facts list (who, what, when, how much, status) taken strictly from the article text. The same facts feed NewsArticle structured data so AI Overviews and answer engines can cite the number instead of paraphrasing the paragraph.

  • Improvement: Entity hubs and running trackers. Each site now has pages for the things it covers repeatedly: threat actors and breached organisations on breached.company, laws on compliancehub.wiki, companies and agencies on myprivacy.blog and scamwatchhq.com, states and vendors on cannasecure.tech, roles and certifications on securitycareers.help, tools and learning paths on hackernoob.tips, exchanges and regulators on cryptoimpacthub.com, devices, brands and building systems on the two SecureIoT sites. Trackers show where each story stands, grouped by jurisdiction, vendor or sector.

  • Improvement: A machine-readable index on every site: llms.txt with the hub structure and llms-full.txt with every article, regenerated on each build. Sitemaps carry a real last-modified date on every article, and three sites that had hand-made sitemaps now generate them properly.

  • Notice: What this is not: no content was rewritten for search engines, no facts were added that the articles did not already state, and no site was interlinked to another for ranking purposes. The work was structural. We will read the effect per site in Search Console after the next core update and report it here.

Improvement

The day-95 rebalance: first full inventory audit, priorities re-tiered, and a hidden-slot bug fixed

With 95 days of clean first-party data (and the CISO.POKER flights retired, freeing our best inventory), we ran the network's first full ad-slot and priority audit — every campaign, every zone, every property. Then we acted on it: priorities re-tiered around measured performance, starved placements given a fair shot, and one measurement-integrity bug fixed the same day.

  • Notice: What the audit showed: our sticky anchor placement converts at 3.1% — roughly 17× the network's leaderboard zones and 60× a typical display ad. The billboard slot quietly runs 1.2%, the best in-page zone by 7×. And nearly 200K monthly impressions were going to placements converting at a fraction of a percent while proven performers waited behind them.

  • Improvement: Priorities re-tiered on evidence: campaigns holding premium tiers on legacy settings moved down, proven converters keep their share, and two security-native partners that had never won a single impression — despite being exactly what this audience buys — got trial slots in the freed inventory. Every change is a two-week measured trial, not a permanent verdict.

  • Improvement: The premium sticky zone freed by CISO.POKER's retirement now belongs entirely to the sponsor coalition's campaigns, and those same sponsors now fill the event-page spotlight and ciso.poker's own sponsor bar — inventory the event once used, handed back to the partners who backed it.

  • Fix: Measurement-integrity fix: on phones, two ad units could render stacked at the bottom of the page — one covering the other. The hidden unit was logging impressions no human could see or click. We stopped serving partner campaigns into the occluded slot the day we found it. If we can't prove an ad was seeable, we don't count it — or charge for it.

  • Notice: Why this matters if you advertise with us: placement decisions here are made from first-party measured CTR, reviewed on a schedule, and corrected in public. The next audit reads out in two weeks.

Resolved

Analytics recording outage (Aug 7–11) — resolved. Ad delivery was never affected.

On August 7 at 01:46 UTC our analytics database hit its 10 GB storage cap (Cloudflare D1) and stopped accepting new events — pageviews, impressions, and clicks went unrecorded for about 4.7 days. Ad serving, click-through redirects, and partner-side affiliate tracking were unaffected the entire time; only our own measurement went dark. Recording resumed August 11 at 19:10 UTC. Here's what happened and what we changed.

  • Incident: Root cause: the nightly maintenance job that summarizes each day's data and prunes old raw events had a one-line SQL bug that made it fail silently every night since launch — so its built-in cleanup never ran once, and 99 days of raw events grew to the database's hard cap.

  • Fix: Freed 2.5 GB by converting 5.19M raw ad-dwell heartbeat pings (44% of all rows — a per-view 'how long was this ad on screen' signal) into permanent daily, hourly, and lifetime aggregate tables. No reported statistic was lost; impressions, clicks, and pageviews were untouched.

  • Fix: The nightly job is fixed and now populates daily summary tables, re-rolls the last 3 days each night so a missed run can't leave holes, refuses to prune anything that hasn't been summarized, and logs failures loudly instead of swallowing them.

  • Notice: August 7–11 traffic is permanently undercounted — you'll see a visible dip in the 30-day charts on the stats page. Partner conversion numbers on affiliate dashboards were tracked normally throughout.

  • Fix: Found while auditing recovery: the stats page's edge-security numbers (threats stopped / blocked / challenged) had been undercounted since Jul 12 — one zone without access to Cloudflare's firewall-events dataset was silently zeroing the counts for 9 of 15 zones that shared its API query, including our most-attacked property. The protection itself was always active (verified rule-by-rule); only the reporting was short. Collection is now per-zone and fault-isolated, and the missing Aug 8–10 traffic snapshots were recovered — including a 35K-threat DEF CON-weekend scanning wave on Aug 8 that the network absorbed while our analytics were down.

Notice

95 days on air: first lifetime numbers, CISO.POKER flights retired, The Stack case study published

The first CyberAdX pixel event fired on May 9, 2026 — 95 days ago. While doing outage recovery we pulled the network's first full lifetime numbers, retired the CISO.POKER house campaigns now that the event window has passed, and published the complete case study of what building The Stack actually took.

  • Notice: Lifetime vital signs (May 9 → Aug 7): 11.9M events across 13 properties — 6.37M ad impressions, 12,412 ad clicks, 191,716 pageviews, 93,819 engaged sessions. Growth: 988k events in May → 5.1M in June → 4.9M in July, with a recent run-rate of ~73k impressions and ~200k events per day.

  • Notice: The premium sticky-anchor zone continues to run 2.3–3.1% CTR (partner campaigns: Nitrokey 3.08%, NovaCustom 2.31%) — 20–60× typical display-industry rates.

  • Notice: The CISO.POKER flights themselves are the network's biggest campaign to date: the apply flight served 234,067 impressions / 2,497 clicks (1.07% CTR) across 17 properties and the sponsor flight 201,519 / 2,352 (1.17%) across 18 — 435,586 impressions and 4,849 clicks through to ciso.poker between May 9 and Aug 6. With the sponsor coalition flights added, the event ecosystem topped 568K impressions and ~5,900 tracked clicks in 90 days.

  • Improvement: CISO.POKER house campaigns (apply + sponsor) are now retired network-wide. That inventory — including majority share of the highest-converting zone on the network — has been released to partner campaigns.

  • Notice: The Stack didn't happen — we canceled 25 hours out, and we published the full case study anyway: the sponsor coalition, the NFC chip system, the 436-message ground game, the numbers above, and exactly how the funding collapsed. Read it on the events page: cyberadx.network/events

Improvement

Stronger sign-in abuse protection: wallet login now bot-challenged and rate-limited

We detected and shut down an automated attempt to mass-create disposable accounts through our wallet (Ethereum) sign-in, then rolled out additional protections across the whole sign-in system. No advertiser, partner, or reader data was involved, and normal sign-ins are unaffected.

  • Improvement: Wallet (Ethereum) sign-in now runs a bot challenge (Cloudflare Turnstile) plus stricter per-address rate limits, so automated scripts can no longer farm accounts through it.

  • Improvement: Blocked the origin of the attempt at the network edge and expanded our datacenter/VPN challenge rules to cover more hosting networks that bots commonly use.

  • Improvement: Proactively hardened the shared identity system behind the network: closed two-factor-authentication gaps on passwordless sign-in paths and encrypted sensitive session data at rest.

Improvement

Expanded network transparency: 30-day metrics, CTR, and edge security on /stats

Our public stats page now shows 30-day impression totals, click-through rates, data served, and live edge-security metrics — and we fixed a brief publishing glitch that showed zeros on Monday morning.

  • Improvement: The /stats page now reports 30-day ad impressions (with daily average), ad clicks, network CTR, and premium-placement CTR from our first-party pixel — real measured numbers, updated weekly.

  • Improvement: New Edge Security section: threats stopped, malicious requests blocked, and bot challenges issued across the network, measured daily at the Cloudflare edge. Advertisers see the traffic-quality enforcement that happens before an impression ever counts.

  • Fix: Fixed the weekly stats publication, which briefly showed zeros on Monday morning due to an expired automation credential and a data-volume milestone (our events store passed 8 million rows, outgrowing the old queries). The pipeline now fails loudly rather than ever publishing incorrect numbers.

Improvement

More accurate impression counts, expanded partner rotation, and bot protections

We fixed a measurement issue that was over-counting ad impressions from inactive browser tabs, expanded our best-performing placement to rotate more partner offers, and added new bot-mitigation and security-visibility measures across the network.

  • Improvement: Ad rotation now pauses in background or idle browser tabs and resumes when the reader returns. Previously, a tab left open kept rotating ads indefinitely, inflating impression counts. Reported impressions are now a more faithful measure of ads a person could actually see.

  • Notice: Stats note: because of the measurement fix above, expect a one-time step down in reported network impressions from Jul 13 onward. This is the removal of over-counted background-tab impressions — reader traffic and ad delivery are unchanged.

  • Improvement: Expanded our highest-engagement placement (the sticky bar) to rotate additional privacy-hardware partner offers alongside existing campaigns, improving relevance and giving partners access to the network's best-converting inventory.

  • Improvement: Added bot-mitigation challenge rules across the content network (verified search-engine crawlers and feeds are unaffected) and began recording daily security-mitigation metrics per property, so we can track and report on blocked or challenged traffic over time.

Improvement

Analytics reliability fix + network-wide edge security baseline

We fixed a subtle bug that occasionally dropped tracking beacons during bursts of activity, and extended our proven edge security protections to every property in the network. Reported stats get slightly more accurate; nothing changes for readers or partners.

  • Fix: Fixed a rare race condition in the analytics pixel that could drop a tracking beacon when several events fired in the same instant (well under 0.1% of traffic). Recovered events mean impression and engagement counts may tick up marginally from Jul 10 onward — that's the fix, not a traffic change. Verified live after deployment.

  • Improvement: Rolled our battle-tested edge security rules out to every property in the network: automated-probe blocking, per-endpoint rate limits, and bot challenges now protect all properties uniformly instead of just the busiest ones. Also closed a set of alternate service URLs that could bypass edge protections.

  • Notice: During a full security sweep we observed (and fully blocked) a spoofed-crawler bot flood aimed at the analytics pixel — none of it reached the stats. Advertiser-facing numbers remain clean: layered validation rejects fake or malformed events before they're counted.

Launch

Affiliate program live + platform security hardening

Our affiliate program is live — earn commissions for referring customers to CISO Marketplace, with reliable tracking and automated payouts. We also added rate-limiting protections across the platform.

  • Notice: Launched the affiliate program end-to-end: affiliates get a referral link, share it, and earn a commission when a referred visitor purchases — credited on the confirmed sale (not browser cookies, so it holds up against ad-blockers and privacy controls). Commissions, rates, and Stripe-powered payouts are managed centrally.

  • Improvement: Hardened the platform edge with rate-limiting and abuse protections across our affiliate, payments, and analytics endpoints, as part of our ongoing Cloudflare Workers deployment. No change to the experience.

Improvement

Ad inventory rebalanced for better-matched placements

We retuned how ads are prioritized and which slots they fill across the network — matching the most relevant offers to the best-performing placements and opening up more standard inventory for partners. No change to the reading experience.

  • Improvement: Rebalanced the network's priority tiers and slot/zone allocation (our internal 'slot matrix') so each placement is matched to the best-fitting campaigns. High-engagement placements are now reserved for the offers that perform best there, while standard banner inventory (leaderboard and medium-rectangle) opens up to a wider rotation of partner offers.

  • Improvement: Dedicated the high-engagement sticky placement to our own event promotion (where it earns the strongest engagement) and freed premium banner slots for rotating partner campaigns — improving relevance and fill without adding clutter.

  • Notice: Stats note: because this changes how impressions are distributed across placements, this period's per-placement breakdown reflects the one-time inventory retune, not a change in traffic. Overall pageviews and reader experience are unaffected.

Improvement

Blog network moved to faster, more secure infrastructure

We migrated all of our content properties to Cloudflare Workers — same content, same URLs, just a faster runtime with stronger security. No change you need to make.

  • Improvement: All 10 Astro blog properties moved from Cloudflare Pages to Cloudflare Workers in a single day. Every URL, redirect, sitemap, and the first-party analytics pixel were preserved 1:1 — it's a platform swap, not a content change, so organic traffic and SEO continue uninterrupted.

  • Improvement: Added modern security headers to every property (HSTS, Content-Security-Policy, X-Frame-Options, and more) — most had none before. Also fixed IndexNow search-engine submissions and the shared contact-form captcha network-wide.

  • Notice: If you notice a brief, minutes-long blip on a single property on Jun 12, that's the secure-certificate handover as each domain moved — not a real outage. Analytics collection carried over without a gap.

Improvement

Free CISO tools + vendor directory now across the network

We're surfacing our own free, interactive CISO calculators and the CISO Marketplace vendor directory across the network — useful tools for readers, no signup required.

  • Improvement: Ten free interactive tools (calculators and assessments) now rotate across the network and inside articles — SASE readiness, SOC build-vs-buy, firewall sizing, endpoint licensing, cloud egress, IoT/OT risk, IAM TCO and more. Free to use, no login.

  • Improvement: The CISO Marketplace vendor directory (48 vetted suppliers across MDR/XDR, SASE, compliance/GRC, IoT/OT, edge/WAF, backup/DR and physical security) is now showcased contextually so readers can find the right vendors by category.

Partners

Partner with CyberAdX through the affiliate networks

Brands can plug into the CyberAdX pixel network through major affiliate networks — Impact, CJ, and PartnerStack among others — plus direct deals.

  • Improvement: New partner avenue: if your program runs on Impact, CJ (Commission Junction), PartnerStack, or another major affiliate network, partnering with CyberAdX is simple — we onboard your creatives and rotate them across our first-party pixel network, contextually matched to the right properties.

  • Improvement: Beyond banners, partners can run coupon/promo cards, deal placements, and native in-article tool cards — all measured with our own cookieless, first-party tracking, so attribution doesn't depend on third-party cookies.

  • Improvement: We match partners by category — security & privacy tooling, and home / office / IoT tech — to the properties where they fit best across the network.

Improvement

Automated weekly transparency stats

Our public /stats page now refreshes automatically, so the numbers you see stay current.

  • Improvement: A scheduled job now pulls our first-party and edge analytics on a regular cadence and updates /stats automatically — no more manual refreshes.

  • Notice: Heads up on the numbers: compliancehub.wiki — normally one of our highest-traffic properties — was offline for a few days in early June (a brief domain lapse, now resolved), which temporarily lowered network-wide pageviews for that week. Traffic is recovering toward its normal baseline.

Resolved

Ad delivery & click tracking restored

Two issues affected the network over the past few weeks. Both are now fixed, and ad fill plus click reporting are back to normal.

  • Incident: Lower ad fill (mid-May–Jun 6): a bot-protection change we rolled out in mid-May turned out to be over-aggressively filtering legitimate ad requests, so many slots showed our house “ad space available” card instead of live ads. We identified the cause and fixed the validation — fill has recovered to normal levels. Bot protection is being re-introduced more carefully.

  • Fix: Click reporting restored: a tracking bug was under-reporting ad clicks network-wide. It's fixed, so click and CTR figures are now accurate again.

  • Notice: compliancehub.wiki downtime (Jun 2–5): the domain briefly lapsed and was promptly renewed. Traffic and ad serving on the property are back to normal.

Improvement

New ad formats + native tool cards

Following the launch we expanded the formats advertisers can run across the network.

  • Improvement: New ad formats: a sticky anchor unit, a billboard placement, coupon/promo cards, and a network-wide hard-bottom sponsor package for always-on premium reach.

  • Improvement: Launched native in-article “tool promo” cards across the blog network — non-intrusive text placements that surface free security tools (microsec.tools, RateMySOC, PhishingRisk, AI Risk Assess and more) to readers mid-article.

  • Improvement: Separated placement (where an ad appears) from format (what it looks like), so new creative types roll out without disrupting existing campaigns.

  • Improvement: Added cisoinsights.show to the carousel network.

Improvement

Anchor ads + fill-rate improvements

Network-wide upgrades to ad placements and serving consistency across all properties.

  • Improvement: New sticky anchor ad unit (mobile + desktop, dismissible) rolled out across all 13 properties.

  • Improvement: Fixed several properties where ad slots weren't firing on non-article pages, improving overall fill rate.

  • Improvement: Added a self-promo fallback so empty slots never sit blank when a passback ad isn't available.

Launch

CyberAdX first-party network goes live

After months of rebuilding, CyberAdX launched its own privacy-first, first-party ad network — monetization we fully own and control.

  • Improvement: First-party pixel deployed across 13 properties — cookieless, no third-party trackers, DNT/GPC honored.

  • Improvement: 6-position carousel ad system with priority-based rotation and server-side, tamper-proof click tracking.

  • Improvement: Public transparency stats published at /stats — real first-party numbers, refreshed weekly.

Improvement

Moved hosting to Cloudflare Pages

Consolidated the network's hosting onto Cloudflare Pages.

  • Improvement: Migrated from Netlify to Cloudflare Pages — bringing serving, edge analytics, and bot protection together at the network edge.

  • Improvement: This is the foundation the first-party ad pixel and bot mitigation now run on.

Launch

Accepted into Cloudflare for Startups

CyberAdX was accepted into the Cloudflare for Startups program.

  • Improvement: Gained access to edge-grade bot mitigation, analytics, and serving infrastructure to rebuild the network on — directly addressing the bot-traffic problem that started this journey.

Improvement

Rebuilt on a faster, static architecture

We rebuilt our properties from the ground up for speed and resilience.

  • Improvement: Migrated off the Ghost CMS onto static Astro sites — lighter, faster, and far more resistant to the kind of automated abuse that took us down.

  • Improvement: Initial hosting on Netlify while the network was being rebuilt.

Incident

A botnet, and a hard reset

Where this all started. A large automated bot network flooded our sites with fake traffic, which led to our removal from Ezoic — the third-party ad platform we relied on at the time. Rather than depend on a platform we didn't control, we chose to rebuild monetization on infrastructure we own.

  • Incident: A botnet generated large volumes of fake, non-human traffic across our properties.

  • Notice: The inflated traffic led to our removal from Ezoic. We treated it as a turning point, not a dead end.

  • Improvement: Decision: build a first-party, privacy-respecting ad network we fully control — the beginning of CyberAdX.

Why we publish this

Advertisers and publishers deserve to know how the network is performing — including when something goes wrong. We post incidents and their resolutions here in plain language, alongside the live numbers on our stats page.

This log contains network-level summaries only — no advertiser identities, per-campaign data, or personal information.

Reach a verified security audience.

Pilots start at $2,500. Managed multichannel packages from $5,000/mo.