Wednesday, September 30, 2026 Newsletter Advertise
Breaking
Products

Cloudflare launches Threat Signals for all accounts, free

Cloudflare says its new agentic skills turn open-source threat reports into tagged, contextualized indicators that can feed WAF rules, with one RSS feed free per account.

Cloudflare launches Threat Signals for all accounts, free. Source: Cloudflare

Cloudflare said on September 29, 2026 that it has launched Threat Signals, a set of agentic AI skills that convert open-source threat reporting into indicators of compromise stored in a private, account-scoped dataset. The company said the feature is generally available to every Cloudflare account via API and the dashboard.

What Cloudflare announced

According to Cloudflare, Threat Signals "turns open-source reporting that you choose into intelligence you can act on." The company said its agentic skills summarize reports, surface key context, extract and normalize indicators of compromise, and apply tags inside a private dataset scoped to the account.

Cloudflare describes a skill as a set of rich, detailed instructions that captures how an experienced analyst handles one part of the job and runs the same way on every report. The company said the end result is a contextualized indicator stored as a Threat Event that can be applied in a customer's WAF policy.

Alongside the launch, Cloudflare said it is expanding access to Cloudforce One's Threat Events Platform, which it calls its core threat intelligence offering, to all Cloudflare accounts for free.

What each account gets

Cloudflare said every account receives API and dashboard access to Threat Signals and the ability to select one RSS feed, a private dataset built from that feed and stored for up to 30 days, and API and dashboard access to the Threat Events Platform to investigate events, indicators and tags tied to the private dataset.

Essentials, Advantage and Elite enterprise customers can extend the offering to include more RSS feeds, access to Cloudforce One's proprietary threat intelligence datasets, the ability to generate custom agentic skills, higher storage options for derived open-source reporting, and the ability to create custom WAF rules on open-source and proprietary threat events, the company said.

How the pipeline works

Cloudflare said Threat Signals uses RSS to monitor open-source reporting, and that customers can add a feed, give it a name and category, and configure how often it is polled. All three feed specifications — RSS 2.0, Atom, and RSS 1.0/RDF — are supported, according to the post.

Each selected feed enters a Workflow that periodically polls for new articles, the company said. Browser Run's Markdown quick action fetches and cleans the article text into markdown, which is stored in R2, and the text is then passed into an indicator of compromise extractor and a set of default Cloudforce One-defined skills that summarize content, apply tags based on account configuration, and add contextualization at the IOC level.

Cloudflare said each extracted indicator is backed by a threat event in the account's private Threat Signals dataset, with the event, its indicators and tags, and the original report staying connected so analysts can trace the source.

Design choices and next steps

Cloudflare said the first version of Threat Signals was a one-week internal prototype built by a threat analyst, and that the harder part was making the output something analysts would trust and use. The company said it limited AI tagging to each account's existing tag catalog after teams pushed back on letting the system invent tags, and that recording whether a tag was applied automatically or by an analyst proved essential to trust.

The company also said customers told it their existing platforms cannot scale beyond polling 100 RSS feeds, which motivated building a more scalable platform. Cloudflare said open-source reporting is not limited to RSS and that it plans to support additional data ingestion pipelines.

What to do

  • Open the Cloudflare dashboard and go to Application Security, then Threat Intelligence, then Threat Signals, to add an RSS feed.
  • Give each feed a recognizable name and category and set how frequently Threat Signals checks for new content.
  • Review Cloudflare's Threat Signals documentation, available from the announcement, for setup details.
  • Enterprise customers on Essentials, Advantage or Elite plans can contact their account team about additional feeds, proprietary datasets, custom agentic skills and custom WAF rules.
Key facts and where they come from
  • Threat Signals launched on September 29, 2026 and is available to every Cloudflare account.
    It's launching today, and we made it available to every Cloudflare account.
  • Cloudforce One's Threat Events Platform is being expanded to all Cloudflare accounts for free.
    we are also expanding access to Cloudforce One's Threat Events Platform, our core threat intelligence offering, to all Cloudflare accounts for free
  • Free accounts get one RSS feed and 30-day dataset storage.
    A private dataset built from the RSS feed in Threat Signals, tailored to your reporting requirements and stored for up to 30 days
  • RSS 2.0, Atom and RSS 1.0/RDF are supported.
    All three feed specifications (RSS 2.0, Atom, and RSS 1.0/RDF) are supported.
  • Article text is cleaned to markdown via Browser Run and stored in R2.
    It uses Browser Run's Markdown quick action to fetch and clean the article text into a readable markdown format, which is then stored in R2.
  • AI tagging is restricted to an account's existing tag catalog.
    So we limited AI tagging to each account's existing tag catalog.
  • Extracted indicators can be used to build WAF rules.
    These indicators can then be used to create WAF rules from threat events to protect your applications and infrastructure.

Read the original from Cloudflare →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Products