Cybersecurity

Cloudflare Connects Risk Discovery, Application Protection, and Security Response in an Adaptive Framework for the AI Era

Cloudflare announced an integrated application security framework that connects vulnerability discovery, agent governance, runtime protection, and incident response within a continuous learning loop. The offering includes capabilities for scanning applications with language models, validating agent traffic, enforcing positive security policies, and expanding access to threat intelligence.

2026-09-29
5 min read
8 views
certi.news Editorial Team
Cloudflare Connects Risk Discovery, Application Protection, and Security Response in an Adaptive Framework for the AI Era

Cloudflare announced a new application security framework aimed at addressing an environment in which software, attacks, and traffic are changing because of artificial intelligence. The core idea is to connect four functions that were often managed separately: discovering and prioritizing risks, managing agent access and behavior, protecting applications at runtime, and then investigating and responding while turning incident findings into stronger controls.

The initiative follows an incident cited by the company that affected parts of OpenAI’s infrastructure and Hugging Face’s production environment. According to the material, agents moved in less than 13 hours from executing code on a Hugging Face worker to obtaining administrative privileges across several clusters, while activity indicators extended from May to July and included creating an unauthorized message board and scanning the internal network. Cloudflare believes the issue was not the ability of artificial intelligence to exploit vulnerabilities in itself, but its ability to continuously test multiple paths, share discoveries, and rapidly connect vulnerabilities, credentials, and permissions in an automated manner.

What Is Changing in the Protection Model?

Cloudflare is advocating for a continuous system rather than a set of tools that waits for each vulnerability to be discovered separately. The framework relies on combining broad threat intelligence with local application context, such as published code, exposed paths, legitimate traffic patterns, and the identities making requests. The company says that its position as a reverse proxy enables it to turn these signals into direct protection policies.

During the discovery phase, the Vulnerability Discovery and Remediation service, currently available through an early access program, links code-scanning results with production traffic to determine whether the affected path is active and how much traffic it receives, with the ability to deploy mitigations through a web application firewall while the code is being fixed. Cloudflare is also developing an Adaptive Security capability to conduct periodic penetration tests on URLs specified by customers, using agents powered by language models to search for vulnerabilities that can be accessed and exploited.

Managing Agent Traffic Instead of Merely Classifying It Automatically

The company says distinguishing between humans and bots is no longer sufficient, because automated requests may come from malicious crawlers, search services, or agents purchasing on behalf of a customer. Cloudflare therefore separates identity, trust, and risk. Botbase provides a directory of registered automated entities, while the platform assesses the entity’s behavioral history, site and identity changes, and request patterns.

Precursor adds signals from the client and session, such as typing rhythm, mouse movement, and browsing sequence. Adaptive Intelligence also combines network, behavioral, and historical signals in an updatable probabilistic model, with the option to use outcomes such as refunds and successful transactions to improve future decisions.

Runtime Protection and Response

Cloudflare also announced Application Profiles, which learn the structure of web applications and APIs and detect requests that do not conform to it, helping teams identify endpoints that require greater scrutiny. The company uses advanced models to test the WAF for bypass techniques, while Attack Score detects changes in attacks and evasion techniques that language models may use. Protection also covers artificial intelligence applications, including prompt injection and data exfiltration attacks, along with tools for business-logic abuse and account takeover.

Cloudflare is also expanding free access to the Cloudforce One Threat Events Platform to all Cloudflare accounts, after threat intelligence-based protection had been available to Cloudforce One customers. The company is working on a security operations platform that connects logs, alerts, and customer context, then uses agents to discover correlations and suggest actions such as rate limiting, modifying WAF rules, or DDoS protection, with a human required to approve the mitigations.

Why Does This Announcement Matter?

The practical value of the offering lies not merely in adding a new scanning tool, but in attempting to connect a vulnerability with traffic and with what happens afterward inside the environment. This matters because the incident Cloudflare cites showed that separate alerts may reveal parts of a single campaign without showing its full sequence. However, some capabilities are still under development or in early access, and security operations agent recommendations require human approval according to the material. Therefore, the announcement alone does not prove that the framework will prevent complex campaigns, but it identifies a practical direction toward connecting discovery, enforcement, and investigation instead of relying on isolated remediation or alerts.

News source
Cloudflare Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news