Skip to content

Cloudflare Gives Every Account Free AI Agents That Turn Threat Reports Into WAF Rules

Short answer

Cloudflare launched Threat Signals, an agentic AI feature that reads RSS threat-intel feeds, extracts and normalizes indicators of compromise, tags them, and links them to WAF rules. It's free on every Cloudflare account starting now, expanding Cloudforce One's Threat Events Platform beyond enterprise tiers.

What this means for operators

Most 10-200 person B2B companies using Cloudflare have nobody dedicated to reading security research and manually converting it into firewall rules — that work either doesn't happen or falls on whoever is free. Threat Signals automates that pipeline: pick an RSS feed relevant to your stack, and the agent summarizes reports, extracts indicators, tags them consistently, and stores them ready to apply as WAF rules with the source context preserved. For a lean ops team, this closes a gap that used to require either a dedicated analyst or ignoring open-source threat reporting entirely.

Cloudflare has launched Threat Signals, a set of agentic AI skills that automate open-source threat intelligence work, and is making its underlying Cloudforce One Threat Events Platform free for every Cloudflare account.

Threat Signals monitors RSS, Atom, or RSS 1.0/RDF feeds chosen by the account, fetches and cleans article text, then runs it through an indicator-of-compromise extractor and a set of default skills that summarize the report, tag it using the account's existing tag catalog, and add context at the indicator level. Each extracted indicator becomes a Threat Event in a private, account-scoped dataset, linked back to the original report, and can be applied directly to WAF policy.

Every account now gets API and dashboard access to Threat Signals, one selectable RSS feed, a private dataset built from that feed and stored for up to 30 days, and dashboard/API access to the Threat Events Platform. Essentials, Advantage, and Elite enterprise customers can extend this to more RSS feeds, Cloudforce One's proprietary datasets, custom agentic skills, longer storage, and custom WAF rules built on proprietary threat events.

Cloudflare says the design choices were shaped by analyst feedback: AI tagging is restricted to an account's own existing vocabulary rather than inventing new tags, and the system records whether a tag was applied automatically or by a human. Early testing reportedly showed analysts valued the persistent link between an indicator and its source report more than the summaries themselves, since that link explains why an indicator was blocked in the first place.

The company frames RSS as a starting point, with plans to add more ingestion pipelines for other threat-intelligence formats.

Threat Signals is generally available now via the Cloudflare dashboard under Application Security → Threat Intelligence → Threat Signals, or via API.

Source: Cloudflare Blog · In the Atlas: Cloudflare OS →

Next step

Discovery Sprint

If that argument holds for your operation, the next step is measuring it. Thirty minutes on one process, and we say whether the arithmetic is likely to close.

Put a time in the calendar

Thirty minutes, free. The sprint is what the call is about.

Fee
$2,500
Length
1-2 weeks

Ends in one of two answers: build this, or do not. The process map, the numbers and the ranked backlog are yours either way.