Skip to content

AI news, read from an operations desk

Most AI coverage is written for people who build models. This is written for people who run processes — every item says what changes for you, or admits that nothing does.

  1. Latest

    Cloudflare Adds Visibility and Controls for MCP Traffic Amid Rising Agent-to-Tool Connections

    Cloudflare announced it can now detect Model Context Protocol (MCP) traffic across its network and offers tools to secure it, including authentication and monitoring for agent-to-tool connections. This matters because MCP is quickly becoming the default way AI agents talk to external tools and data sources, and most companies have no visibility into that traffic today.

    What changes for operatorsIf your team has connected any AI agent — a support bot, a sales assistant, an internal ops tool — to external data sources or software using MCP, that traffic has likely been invisible to your IT or security stack until now. For a 10-200 person B2B company, this is rarely a dedicated security team's job to catch; it's usually whoever wired up the integration last quarter. The practical takeaway is not "adopt Cloudflare" — it's a prompt to ask your ops or engineering lead a direct question: which tools in our stack are making MCP connections, who authorized them, and can we see what data is flowing through them? If the answer is a shrug, that's the gap this announcement is surfacing.

  1. Cloudflare Ships Certificate Transparency Monitoring to All Customers

    For a 10-200 person B2B company, this is a quiet but useful upgrade to your security posture, not something that changes daily workflow. If your domains sit behind Cloudflare, you now get free, automatic notice if someone issues a certificate for your domain, support portal, or customer-facing subdomain without your knowledge — a common precursor to phishing campaigns targeting your customers or employees. The practical move is to confirm the feature is switched on and routed to whoever owns IT/security (often a founder or ops lead wearing multiple hats at this size), and to make sure alerts land somewhere that gets checked, not a dead inbox. This isn't a reason to change your automation stack or support workflows, but it's a legitimate, no-cost reduction in one specific risk: a spoofed certificate being used to impersonate your login page or API endpoints to your own customers.