DEV Community

Mikhail Savchenko
Mikhail Savchenko

Posted on Originally published at inite.ai

Cloudflare Gives Every Account Free AI Agents That Turn Threat Reports Into WAF Rules

Cloudflare has launched Threat Signals, a set of agentic AI skills that automate open-source threat intelligence work, and is making its underlying Cloudforce One Threat Events Platform free for every Cloudflare account.

Threat Signals monitors RSS, Atom, or RSS 1.0/RDF feeds chosen by the account, fetches and cleans article text, then runs it through an indicator-of-compromise extractor and a set of default skills that summarize the report, tag it using the account's existing tag catalog, and add context at the indicator level. Each extracted indicator becomes a Threat Event in a private, account-scoped dataset, linked back to the original report, and can be applied directly to WAF policy.

Every account now gets API and dashboard access to Threat Signals, one selectable RSS feed, a private dataset built from that feed and stored for up to 30 days, and dashboard/API access to the Threat Events Platform. Essentials, Advantage, and Elite enterprise customers can extend this to more RSS feeds, Cloudforce One's proprietary datasets, custom agentic skills, longer storage, and custom WAF rules built on proprietary threat events.

Cloudflare says the design choices were shaped by analyst feedback: AI tagging is restricted to an account's own existing vocabulary rather than inventing new tags, and the system records whether a tag was applied automatically or by a human. Early testing reportedly showed analysts valued the persistent link between an indicator and its source report more than the summaries themselves, since that link explains why an indicator was blocked in the first place.

The company frames RSS as a starting point, with plans to add more ingestion pipelines for other threat-intelligence formats.

Threat Signals is generally available now via the Cloudflare dashboard under Application Security → Threat Intelligence → Threat Signals, or via API.

Top comments (0)