blog.cloudflare.com 29 Sept 2026, 13:00 UTC

Cloudflare Turns Open Source Reports Into Instant WAF Defences

Cloudflare Turns Open Source Reports Into Instant WAF Defences
CyberSIXT Evidence Panel Source marked as original reporting

CLOUDFLARE has launched Threat Signals, an AI-assisted workflow that scales threat intelligence by transforming open-source reports into actionable indicators. The feature uses agentic skills to read, summarise, contextualise, extract indicators of compromise, and apply tags, all within a private, account-scoped Threat Intelligence dataset. The output is a contextualised threat event that can be applied immediately in a user’s WAF policy, bridging the gap between discovering an alert and taking remediation actions.

Threat Signals taps open-source reporting via RSS feeds (RSS 2.0, Atom, and RSS 1.0/RDF) and feeds them into a configurable workflow. It fetches and cleans article text, stores it in R2, runs an IOC extractor, and uses predefined Cloudforce One skills to produce summaries and tags while preserving links to the source report.

Each extracted indicator stays linked to a threat event in the account’s private Threat Signals dataset, enabling analysts to trace intelligence back to its origin and to create WAF rules from threat events. The system is now generally available for every Cloudflare account, with API and dashboard access to Threat Signals and a private dataset retained for up to 30 days. Essentials, Advantage, and Elite customers can extend feeds, access proprietary datasets, and generate custom agentic skills.

organisations should navigate to the Cloudflare dashboard (Application Security → Threat Intelligence → Threat Signals) to add RSS feeds and begin investigative workflows. The article emphasises maintaining contextual links between reports, indicators, and investigations to sustain trust in automated tagging and parsing.

View full article

Article by CyberSIXT