Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
From the source: Cloudflare BlogWe are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.
Read the full story on Cloudflare BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from Cloudflare
Recent updates from Cloudflare, so you can tell whether this is a one-off or part of a pattern.
Streamline: custom video pipelines with Cloudflare Stream and Workers
Streamline demonstrates how to build long-running, continuous video processing pipelines by pairing Cloudflare Workers and Durable Objects with a containerized media engine.
Introducing Web Search API via AI Gateway
Cloudflare AI Gateway now supports native web search API integration in partnership with Ceramic.ai, Exa, and Linkup. Developers can now inject real-time web context into model inference calls via AI Gateway, REST APIs, or Workers bindings.
Follow the thread: a new dashboard to investigate account abuse
Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.
More in Security
What other companies in Security are doing. The category page shows who’s active, side by side.
Threat Actors Use Google Ads To Target Ledger Users
In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…
Updates on our pledge to make Cloudflare features accessible to everyone
A year after pledging to eliminate two-tier product access, Cloudflare has expanded Logpush, multi-account governance, and higher platform limits to all accounts. Here is an update on our progress, how we dogfood these tools internally, and what is coming next.
Announcing Cloudflare OHTTP Gateway: expanding access to Cloudflare’s privacy-preserving infrastructure
We’re announcing the closed beta of a self-serve Cloudflare OHTTP Gateway. We’re also renaming our Privacy Gateway to Cloudflare OHTTP Relay to better distinguish the two products.
Protected Quick Tunnels: simple accountless authentication for your next dev project
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
