Lifestyle

Cloudflare launches Threat Signals: free AI tools that turn public security reports into usable threat intelligence for every account

On September 29, 2026, Cloudflare announced Threat Signals, which uses AI agentic skills to turn open-source security reports that users select into usable indicators of compromise. It also made the Threat Events Platform free. This article outlines the features, the differences between free and enterprise plans, and what it means for people who run websites on Cloudflare, based on Cloudflare's official statements.

About 6 min read

Cloudflare launches Threat Signals: free AI tools that turn public security reports into usable threat intelligence for every account
Image: Mokaair (Original editorial artwork)

What Cloudflare announced

According to Cloudflare's official blog, the company launched Threat Signals on September 29, 2026. It says the feature is now generally available to every Cloudflare account through the API and dashboard. Threat intelligence is information about online attacks and the infrastructure behind them. "Open-source" reports are research that security researchers publish openly. Cloudflare says Threat Signals turns open-source reports that users choose themselves into actionable intelligence. Its agentic skills summarize each report, extract key context, extract and normalize indicators of compromise, and apply tags. Indicators of compromise are clues such as IP addresses or domains linked to an attack. The results are stored in a private dataset specific to the account.

Cloudflare describes a "skill" as a set of detailed instructions that captures how a senior analyst handles a particular part of the work, applied the same way to every report. The company says the final output is a Threat Event stored in the account's private threat intelligence dataset. That Threat Event can be applied to WAF (web application firewall) policies; a WAF filters traffic before it reaches a website or app. Cloudflare also announced that it is making Cloudforce One's Threat Events Platform free for all accounts.

Cloudflare launches Threat Signals: free AI tools that turn public security reports into usable threat intelligence for every account
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

Why tackle "unstructured" security reports

Cloudflare notes that security teams have long been able to ingest structured threat data, meaning ready-made machine-readable feeds, automatically. The harder part is unstructured research articles written for people. By its account, analysts have to read and summarize reports, identify indicators and normalize their formats. They then tag them according to internal taxonomies, import them into a threat intelligence platform, keep the original link and share them with the team. Cloudflare argues that when these steps are repeated, indicators easily become separated from the context explaining why they matter, leading to lost context.

Cloudflare also says customers reported that their existing platforms could not scale to polling more than 100 RSS sources, which was one of the reasons it developed this feature. RSS is a standard format that websites use to publish a feed of new articles.

How it works: from RSS to WAF rules

  1. Add sources: Cloudflare says RSS 2.0, Atom and RSS 1.0/RDF are supported, and sources can be named, categorized and given a check frequency.
  2. Fetch and clean: According to Cloudflare, each source enters a Workflow that regularly checks for new articles. Its Browser Run tool fetches and cleans the articles into Markdown text, which is stored in Cloudflare's R2 storage.
  3. AI processing: The text is passed to an IOC extractor and Cloudforce One's default skills, which produce summaries, key points and tags.
  4. Create events: Cloudflare says each indicator maps to a threat event in the private dataset and stays linked to the original report.
  5. Apply protection: These indicators can be used to create WAF rules from threat events.

Free accounts vs. enterprise plans

Compiled from Cloudflare's official blog; not independently verified
ItemAll accounts (free)Essentials / Advantage / Elite enterprise customers
Number of RSS sourcesOneCan expand to more
Data retentionPrivate dataset up to 30 daysHigher storage available
Threat Events PlatformAPI and dashboard for investigating events related to the private datasetAlso access to Cloudforce One proprietary datasets
Agentic skillsCloudforce One default skillsCan generate custom agentic skills
WAF rulesCan create WAF rules from threat eventsCan create custom WAF rules for open-source and proprietary threat events

Design trade-offs Cloudflare shared

Cloudflare says the first version of Threat Signals was an internal prototype built by one threat analyst in a week. It says the real difficulty lay in making the output trustworthy. The company restricts AI tags to each account's existing tag catalog, so analysts do not have to map new terms separately. It also records whether each tag was applied automatically or by an analyst, and says this made analysts more willing to trust automatic tags. Cloudflare also says that in early testing, analysts relied most on the link between an event and its original report.

What it means for everyday readers and small teams

Some individuals and small teams run websites without dedicated security staff. For them, Cloudflare says this feature can turn public security reports into indicators with sources and explanations attached, and connect them to WAF protection. That could reduce the burden of manual reading and organizing. However, the free tier is limited to one RSS source and 30 days of retention, so the real benefit depends on the quality of the chosen source. This article is not a purchase recommendation; assess whether you need an enterprise plan against your own needs. Cloudflare also says it will support more data ingestion channels beyond RSS in the future.

Frequently asked questions

What is Threat Signals?

According to Cloudflare, it is a feature that uses AI agentic skills to process open-source threat intelligence. It reads articles from the RSS sources you choose and produces summaries. It also extracts and normalizes indicators of compromise and applies tags. The results are stored in the account's private dataset, where they can then be used for WAF rules.

Does it cost anything?

Cloudflare says the feature is open to every Cloudflare account. Free accounts can choose one RSS source with data retained for up to 30 days. More sources, proprietary datasets and custom skills fall under the expanded offering for Essentials, Advantage and Elite enterprise customers.

Where do I turn it on?

Cloudflare says you can add RSS sources in the dashboard under Application Security → Threat Intelligence → Threat Signals, or use it through the API.

Will the AI invent its own tags?

Cloudflare says no. AI tags are restricted to each account's existing tag catalog, and the system records whether a tag was applied automatically or by an analyst.

Which source formats are supported?

According to Cloudflare, RSS 2.0, Atom and RSS 1.0/RDF are currently supported. The company says more data ingestion channels will be added in the future.

Have these claims been independently verified?

No. This article is based solely on Cloudflare's official blog. These are vendor statements, and users and third parties have yet to test how well it works.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle