Cybersecurity

Cloudflare Makes Threat Signals Free for All Accounts to Turn Threat Reports into Protection Rules

Cloudflare launched Threat Signals to subject open-source threat intelligence reports to automated analysis, extract indicators of compromise, and link them directly to WAF policies. It also expanded free access to the Threat Events Platform for all accounts, with higher limits and proprietary sources available to enterprise customers.

2026-09-29
4 min read
2 views
certi.news Editorial Team
Cloudflare Makes Threat Signals Free for All Accounts to Turn Threat Reports into Protection Rules

Cloudflare announced that Threat Signals is available to all its accounts through the dashboard and API, in a step aimed at turning open-source threat intelligence reports from text that is difficult to operationalize into actionable indicators inside defense tools. The service extracts indicators of compromise, summarizes reports, adds context and tags, and then stores the results in an account-specific dataset that can be used to create WAF rules.

What does Threat Signals provide?

The service monitors RSS sources specified by the customer and supports RSS 2.0, Atom, and RSS 1.0/RDF. When a new report arrives, it uses a workflow to fetch and clean the text, then passes it to indicator-of-compromise extraction tools and default skills developed by Cloudforce One. The results include a summary of the text, its key points, and classification according to the tag catalog in the account, with each indicator linked to the original report in which it appeared.

The results are stored in an account-scoped dataset for up to 30 days under the offering available to all accounts. The extracted indicators become Threat Events that can be searched and investigated, and they can also be used to create WAF rules to protect applications and infrastructure.

Expanding access to the Threat Events Platform

Alongside the launch of Threat Signals, Cloudflare made the Threat Events Platform available to all accounts for free, with access through the dashboard and API to investigate events, indicators, and tags associated with the private dataset.

Each account can select one RSS source. Customers on the Essentials, Advantage, and Elite enterprise plans can expand the service to obtain a larger number of sources, access proprietary Cloudforce One datasets, create custom skills, increase storage options, and create custom WAF rules based on open-source or proprietary events.

Why does this change matter?

The problem Cloudflare is targeting is not reading RSS feeds itself, but turning unstructured reports into information that retains its context. An analyst typically needs to summarize the report, extract and normalize the indicators, classify them, and enter them into a threat intelligence platform, while retaining the link that explains their source and why they matter.

According to Cloudflare's presentation, separating an indicator from the original report leads to loss of context, and the result may be that a domain is added to a blocklist weeks later without the team knowing why the decision was made. Keeping the event, indicators, tags, and original report linked enables the analyst to review the source and understand the importance of each indicator during investigation or remediation.

Limitations and points worth noting

Free availability does not mean that operational restrictions have been removed; the basic plan is limited to one RSS source and storage of its derivatives for up to 30 days. The quality of the results also remains tied to the sources selected by the customer and the ability of automated extraction to interpret the reports. Cloudflare says it limited automated tags to each account's tag catalog and recorded whether a tag was added automatically or by an analyst, with the goal of facilitating review and building trust.

The company says RSS is only the starting point and that it is working on supporting other pathways and formats for ingesting threat intelligence. Until those pathways become clear, the current practical value remains focused on organizations that rely on RSS reports and want to reduce manual work before applying indicators to WAF policies.

News source
Cloudflare Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news