CLOUDFLARE describes an internal experiment testing its own Web Application Firewall (WAF) against frontier AI models acting as simulated attackers. The team built a dynamic testing loop where an LLM is given a starting exploit, then proposes variations in encoding or delivery, with a human reviewer assessing any non-blocked requests. The tester ran 1,107 attempts across six attack categories, starting from an authorised customer staging environment and using an allowlisted User‑Agent.
The vast majority of attacks were blocked by the WAF, though some through‑traffic observations yielded actionable detections and led to hardening work. The exercise emphasised that a payload bypassing the WAF still requires an exploitable application and that patching and up‑to‑date stacks remain essential.
Six attack categories were pursued, including XSS, SQL injection, command injection, SSRF, path traversal/LFI, and Log4j, with a separate log‑injection case noted. After triage, 49 findings were identified as WAF‑relevant, mainly tied to CMDi and SSRF, and 558 requests were blocked before reaching the origin.
The report details how attempts were evaluated, how many became detections, and how findings informed rule changes in Cloudflare’s Managed Ruleset—specifically SSRF expansions such as Obfuscated Host and Restricted Protocol, and improvements to SSRF‑Cloud. The authors advise customers to deploy the full suite of protections, validate legitimate traffic, and consider signature detections, while reiterating that strong defence also depends on keeping software up to date.