← Back to blog

Redson Dev brief · PRIMARY SOURCE

ARTICLE#Dev#AI

Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account

Cloudflare Blog · September 29, 2026

Securing your digital assets against evolving threats just became significantly more accessible, even for those without dedicated security teams. Cloudflare has introduced "Threat Signals," a new capability that automatically processes open-source threat intelligence, extracts actionable indicators, and directly integrates these insights into your Web Application Firewall (WAF) rules. This means that as new vulnerabilities or attack patterns emerge and are reported publicly, your defenses can automatically adapt without manual intervention, strengthening your security posture against sophisticated, real-time threats. This development offers a substantial advantage by democratizing advanced threat intelligence. Consider a small e-commerce shop based in Austin, Texas, selling handcrafted goods. Historically, monitoring the vast landscape of threat reports and manually updating WAF rules was impractical for them. With Threat Signals, their Cloudflare WAF can automatically incorporate new indicators related to credential stuffing or SQL injection attempts reported from global sources, protecting customer data and sales without requiring a full-time security analyst. Likewise, an indie SaaS founder in Seattle, Washington, building a niche project management tool can now offer a more robust service. Instead of relying solely on generic WAF rules, their application benefits from dynamic protection that adapts to newly discovered botnet IP ranges or phishing domains, ensuring their platform remains available and secure for subscribers and reducing the risk of costly breaches. Even a logistics startup operating out of Chicago, managing sensitive delivery routes and inventory data, can leverage this. Their operational dashboards and APIs, if protected by Cloudflare, will automatically gain updated defenses against new forms of DDoS or API abuse as soon as those tactics are identified and reported in the broader security community. The practical impact is that developers, founders, and operators can shift focus from reactive security patching to proactive innovation, confident that baseline protections are continuously hardening. It mitigates the common challenge where smaller organizations lack the resources to keep pace with the rapid cadence of new threat intelligence, a gap often exploited by attackers. By automating this critical function, businesses can maintain strong defenses against threats that might otherwise go unnoticed or take too long to mitigate manually, reducing downtime and protecting sensitive information more effectively. To capitalize on this, access your Cloudflare dashboard this week, navigate to your WAF settings, and explore the new Threat Signals integration. Examine the types of intelligence it can ingest and how it suggests applying rules to your existing web properties, perhaps starting with a non-critical staging environment to observe its automated updates in action.

Source / further reading

Learn more at Cloudflare Blog →