Cloudflare today opened its Threat Events Platform to all customers at no charge and released Threat Signals, a set of AI skills that reads published security research, pulls out indicators of compromise and files each one as a tagged event in a private, account-scoped dataset.
In Short
Cloudflare, the company that sits in front of a large share of the world's websites, now lets every customer, including those who pay nothing, have an AI system read each new report from a source of security research they pick. That matters to anyone running a website, because the system picks out the web addresses and other clues attackers leave behind, labels them and keeps them for 30 days next to a summary and a link to the original report. What changes is that small sites get a version of work that large security teams used to do by hand, while paying customers get more sources, longer storage, Cloudflare's own private data and custom instructions for the AI.
Two changes in one post
The details were set out in a post on the Cloudflare blog written by Emilia Yoffie, Victor Niño, Brian Seel and Jacob Crisp and carried under the company's Birthday Week banner. It bundles two separate moves. The first is Threat Signals, a product that monitors open-source security reporting selected by the customer and converts it into structured intelligence. The second is broader: access to the Threat Events Platform, which Cloudflare describes as the core threat intelligence offering of Cloudforce One, its in-house threat intelligence unit, is being extended to all Cloudflare accounts for free.
"Organizations can now scale threat intelligence expertise the way they scale infrastructure," the post opens.
Under the free arrangement, according to Cloudflare, each account receives three things. There is API and dashboard access to Threat Signals, with the ability to select a single RSS feed. There is a private dataset built from that feed, tailored to the account's reporting requirements and stored for up to 30 days. And there is API and dashboard access to the Threat Events Platform itself, for investigating the events, indicators and tags that relate to the account's own dataset.
Customers on the Essentials, Advantage and Elite enterprise tiers can go further in five respects: a larger number of feeds, access to Cloudforce One's proprietary threat intelligence datasets, the ability to generate custom skills, higher storage options for the open-source reporting Threat Signals derives, and custom web application firewall (WAF) rules built on both open-source and proprietary threat events. The post does not quantify the larger feed allowance or the storage options. It publishes no prices.
Threat Signals is generally available through the API and the dashboard, where it sits under Application Security and then Threat Intelligence, according to Cloudflare.
A discrepancy over firewall rules
The post is not consistent about what an unpaid account can do with its indicators at the firewall. Its opening section says the end product of the pipeline is a contextualized indicator, stored as a Threat Event, that "can instantly be applied" in a customer's WAF policy. A later passage states that extracted indicators "can then be used to create WAF rules from threat events". Yet the list of enterprise extensions includes "the ability to create custom WAF rules on open-source and proprietary threat events".
Cloudflare does not explain how a custom rule differs from applying a threat event to WAF policy. As published, it is unclear whether an account on the free arrangement can act on its indicators at the edge of its network, or only investigate them.
A backlog built by hand
Researchers regularly publish detailed findings on vulnerabilities, malicious infrastructure, phishing campaigns, malware families and threat actors, and feed readers make new reporting easier to find. Cloudflare's argument is that discovery is only the beginning. Threat intelligence analysts and network defenders have long automated the ingestion of structured threat feeds into security information and event management (SIEM) systems and WAFs, the post notes. The harder work has always been unstructured reporting: turning a research post into indicators a tool can use without losing the context that explains why they matter.
Before a report becomes usable, according to Cloudflare, an analyst has to read and summarize it, identify the relevant indicators, convert their values into a consistent format, classify the report against an internal tagging taxonomy, load the indicators into a threat intelligence platform (TIP), preserve a link to the original source and share the result with the rest of the security team. Seven steps, repeated across dozens of sources, with almost every one resting on human judgment. "Expertise has never been something organizations can replicate at scale," the authors write.
The failure they describe will be familiar to many security teams. Indicators are inserted into a TIP separated from the reasoning that explains them and helps assess risk later in the remediation cycle. "It's not surprising that weeks later, a domain is pushed to a blocklist and nobody understands why."
Scale is the second grievance. Cloudflare says customers told it their existing platforms "cannot scale beyond polling 100 RSS feeds", and it describes its own goal as an "infinitely scalable platform". The post promises more on that point but never returns to it with figures - no throughput, no minimum polling interval, no count of feeds handled in testing. What does an infinitely scalable platform look like on a single feed? The free allowance is one hundredth of the ceiling customers complained about.
How the pipeline works
Setting up a source, according to Cloudflare, means adding the feed, giving it a recognizable name and a category, and configuring how often Threat Signals checks for new content. All three common feed specifications are supported: RSS 2.0, Atom and RSS 1.0/RDF.
Each feed is placed into a Workflow that periodically polls for new articles. The capitalized name matches Cloudflare Workflows, the durable execution engine that reached general availability in April 2025, in which each step is independently retriable and state persists between steps. When a new item appears, the Markdown quick action in Browser Run, another Cloudflare product, fetches the article and cleans its text into readable markdown, which is then stored in R2, Cloudflare's object storage.
Markdown as the working format fits a line Cloudflare has pursued for most of this year. When the company released Markdown for Agents on February 12, 2026, its own announcement post measured 16,180 tokens as HTML against 3,150 as markdown. That product converted pages for AI systems on the publishing side. Threat Signals applies the same conversion on the reading side.
From storage, the text is passed into an indicator of compromise (IOC) extractor and into a default set of skills defined by Cloudforce One. The skills summarize the content, apply tags based on the account's configuration and add contextualization at the level of each individual IOC. The output is a concise summary with key points, meant to let an analyst see quickly what happened, who was affected and why the report matters. All of it is searchable and tagged.
Finally, each extracted indicator is backed by a threat event within the account's private Threat Signals dataset. The event, its indicators and tags, and the original report stay connected, according to Cloudflare, so an analyst can always trace where a piece of intelligence came from and why it is there.
What Cloudflare means by a skill
The product rests on one word. "A skill is a set of rich, detailed instructions that captures how an experienced analyst handles one part of the job, and it runs the same way on every report," the post states. Cloudflare calls the skills agentic, and the tasks assigned to them - summarizing reports, surfacing context, extracting and normalizing indicators and applying tags - all run inside the private, account-scoped dataset.
Instruction files of this kind reached advertising technology earlier this year. On July 11, 2026, Adform published 29 read-only skills for its FLOW demand-side platform, each a single markdown file setting out purpose, example queries, usage constraints and presentation guidance, none able to change a campaign. Adform's skills end in a report. Cloudflare's end in a stored security event that the post connects to firewall policy.
Several technical particulars are left out. The post does not name the models that run the skills. It does not say whether the IOC extractor is a language model, a set of matching patterns or a combination of the two. Nor does it describe what a custom skill on an enterprise tier may contain.
What testing changed
According to the post, the first version of Threat Signals was a one-week internal prototype, built by a threat analyst who wanted more out of the reports she was already reading. The authors are frank that parsing was the easy part. "It's not hard to write a script that pulls an RSS feed and regexes IP addresses out of it," they write. Turning the prototype into something every account could rely on was harder, and most of what slowed the team had nothing to do with parsing. "The hard work was in making the output something analysts would trust and actually use."
Three design decisions came out of that work.
Tag vocabulary. The team was tempted to let the system invent whatever tags seemed useful. Teams it consulted pushed back, arguing that intelligence labeled in an unfamiliar vocabulary is harder to use, "because now there are two vocabularies to reconcile". AI tagging was limited to each account's existing tag catalog.
Tag provenance. Threat Signals records whether a tag was applied automatically or by an analyst. That sounded like a minor piece of metadata, the authors write, but it turned out to be essential: "In our experience, analysts were far more willing to trust automatic tagging when they could see exactly which tags it applied."
Source links. Summaries are what users notice first. In early testing, though, analysts kept returning to the link between an event and the report it came from, and as investigations progressed that link helped them keep track of indicators and understand why each one mattered.
None of the three is a claim about model accuracy. Each is a way for a person to check the machine's work. Cloudflare publishes no precision or recall figures for extraction, no error rate for tagging and no count of reports processed during testing.
Questions the post leaves open
Two risks that apply to any language model reading outside material go unmentioned. The first is prompt injection, in which text a model was meant to treat as data is obeyed as an instruction. Threat Signals reads third-party writing by design. UK regulators have warned that the risk is amplified when an agent autonomously ingests content from multiple sources, a concern raised again when Cloudflare added MCP traffic detection to its Gateway product on August 14, 2026. What happens when the report is itself the attack? The post does not say how the skills separate a report's content from instructions embedded in it, or what would stop a doctored post from listing a legitimate domain among its indicators. Exposure is bounded by the fact that each account chooses its own sources.
The second is hallucination: a model producing text shaped like an answer that its source does not support. A summary that misstates who was targeted is a nuisance. An indicator that never appeared in the report could become a false block. Keeping every event tied to its source report gives analysts a way to catch both, even though the post presents that link as a usability finding rather than a safeguard.
A third question concerns the researchers whose work feeds the system. Browser Run fetches each article, a markdown copy is written to R2, and a summary is produced for an analyst who may never open the original. Cloudflare has built much of its recent product work around what AI systems owe the sites they read; on July 1, 2026, it moved from charging AI crawlers per fetch toward paying publishers when their content contributes to an answer. The Threat Signals post preserves a link to every source. It does not say whether Browser Run's fetch identifies itself, honors robots.txt or reads the content-use preferences Cloudflare lets site owners declare, and it does not say how long the markdown copies in R2 are retained.
Birthday Week and the free tier
Threat Signals was one of several posts Cloudflare published today. Others included a piece by Sharon Goldberg and Tiago Silva on using AI to plan a post-quantum migration, one by Steve Goldsmith on building a certificate authority for the whole Internet, and one by Daniele Molteni, Jonathan Spies and Christian Reilly on how the company connects code, traffic and intelligence in application security.
Releasing tools to unpaid accounts during Birthday Week is an established pattern. On September 27, 2024, Cloudflare added 15 new features for free-tier users, and among the benefits it listed from running a free tier was threat intelligence gained from exposure to diverse traffic and attacks. On September 26, 2025, Observatory and Smart Shield entered open beta on every subscription tier, free accounts included.
The commercial structure of this release is plain enough. Unpaid accounts receive the pipeline and the investigation platform. The proprietary datasets, additional feeds, larger storage and custom skills belong to the three enterprise tiers, and the post closes by pointing readers to their account teams about putting Threat Events to work in enterprise environments.
Cloudforce One's name runs through both halves: it defines the default skills and it operates the platform. The same unit wrote the inaugural 2026 Threat Report, published on March 3, 2026, which found that 94% of login attempts across Cloudflare's network originated from bots, that 63% of logins involved credentials already compromised elsewhere, and that 46% of analyzed emails failed DMARC.
Why this matters for the marketing community
Advertisers, agencies and publishers are targets of the threats these reports describe, not only buyers of the products that counter them. On July 23, 2026, Confiant documented the SourTrade malvertising campaign, which impersonated TradingView, Solana and Luno across 12 countries and 25 languages and assembled its malware inside victims' browsers so that no finished file ever crossed the network. Research of that kind is the unstructured material Threat Signals is built to read: a narrative, a list of infrastructure and an argument about why it matters.
Context is also where indicators touching marketing infrastructure become awkward. Cloudforce One's threat report documented attackers using Google Drive, Dropbox, GitHub, Google Calendar, Microsoft Teams and Amazon S3 as command-and-control infrastructure, and marketing teams depend on several of those services daily. An indicator pointing at such a service cannot be blocked wholesale without collateral damage; the reason it was flagged is what determines the response. Keeping the report attached to every event speaks to that problem, in principle if not yet in any published results.
For small publishers and advertisers running sites on Cloudflare without a paid contract, the release opens investigation tooling the company had not previously extended to every account. Whether it reaches the firewall depends on the unresolved question over WAF rules.
The skills format also continues a pattern visible across advertising technology this year, as vendors package expertise into reusable instructions for AI systems. Adform confined its skills to reading. Cloudflare's write tags and events automatically, while keeping a record of which labels a machine applied rather than a person. Governance debates in ad tech have turned on the same line between reading and acting, and on how much of an agent's work can be audited afterwards.
The release also lands in a year of staff cuts across security and infrastructure companies. Cloudflare cut about 1,100 jobs in May 2026, roughly 20% of its workforce, and chief executive Matthew Prince defended the decision in a Wall Street Journal op-ed. In June, cuts reached Google's Threat Intelligence Group and Mandiant. Cloudflare's post does not present Threat Signals as a substitute for analysts, and most of its design section recounts changes made because analysts asked for them. A product pitched on scaling expertise "the way they scale infrastructure" will nonetheless be read against that backdrop.
What comes next, according to Cloudflare, is more data ingestion pipelines, since open-source reporting is not limited to RSS. The post gives no timetable.
Timeline
- September 27, 2024 - Cloudflare adds 15 new features for free-tier users, listing threat intelligence among the benefits of running a free tier
- April 2025 - Cloudflare Workflows reaches general availability as a durable execution engine with independently retriable steps
- September 26, 2025 - Observatory and Smart Shield enter open beta on every Cloudflare subscription tier, free accounts included
- February 12, 2026 - Cloudflare releases Markdown for Agents; its announcement post measures 16,180 tokens as HTML against 3,150 as markdown
- March 3, 2026 - Cloudforce One publishes its inaugural 2026 Threat Report, finding 94% of login attempts come from bots
- May 2026 - Cloudflare cuts about 1,100 jobs, roughly 20% of its workforce
- June 4, 2026 - Cuts reach Google's Threat Intelligence Group; Mandiant is also affected
- July 1, 2026 - Cloudflare moves from charging AI crawlers per fetch toward paying publishers per answer
- July 11, 2026 - Adform publishes 29 read-only skills for its FLOW demand-side platform
- July 23, 2026 - Confiant documents the SourTrade malvertising campaign across 12 countries and 25 languages
- August 14, 2026 - Cloudflare adds MCP traffic detection to Gateway
- September 29, 2026 - Cloudflare releases Threat Signals as generally available and opens the Threat Events Platform to all accounts, with one feed and 30 days of storage on the free arrangement
- Undated - Additional data ingestion pipelines beyond RSS
Related PPC Land coverage
- Cloudflare's 2026 threat report: attackers ditch hacking for smarter exploitation - Cloudforce One's first annual report, with bot login figures and the abuse of cloud services as command-and-control infrastructure.
- SourTrade malvertising builds malware inside browsers, hits 12 countries - Confiant's research on a campaign impersonating TradingView, Solana and Luno while evading file scanning.
- Adform gives AI agents 29 read-only skills to query FLOW DSP - An advertising platform's markdown skill files and the read-only design behind them.
- Cloudflare cuts AI token costs by 80% with markdown conversion - How Markdown for Agents converts HTML for AI systems and the token savings Cloudflare measured.
- Cloudflare Gateway blocks MCP calls that bypass approved portals - Cloudflare's network-level controls on agent traffic and the blind spots they leave.
- Cloudflare unveils major AI Agent development tools - The Developer Week 2025 releases, including general availability of Workflows.
- Cloudflare stops charging AI per crawl and starts paying per answer - The July 2026 shift in how Cloudflare prices AI access to publisher content.
- Cloudflare reinforces Free Tier commitment with 15 new features announcement - The 2024 Birthday Week free-tier release and the benefits Cloudflare attributed to it.
- Cloudflare launches Observatory and Smart Shield for website performance - The 2025 Birthday Week monitoring release offered across all tiers, including free.
- Cloudflare CEO expects bot traffic to hit 1,000 times human within 5 years - Matthew Prince on machine traffic, micropayments and the company's May 2026 layoffs.
- Google quietly cut its cyber threat team while betting billions on AI - The June 2026 cuts to Google's Threat Intelligence Group and Mandiant.
- HUMAN Security launches open-source MCP server for AI threat analysis - An earlier effort to put threat intelligence behind conversational AI interfaces.
- Cloudflare opens anonymized speed data from 10,000 top websites - Another Birthday Week release, the BEACON real-user performance dataset.
Summary
Who: Cloudflare, through a blog post by Emilia Yoffie, Victor Niño, Brian Seel and Jacob Crisp, with Cloudforce One, its in-house threat intelligence unit, defining the default skills and operating the Threat Events Platform. The release affects every Cloudflare account, customers on the Essentials, Advantage and Elite enterprise tiers, security analysts, and the researchers whose published reports feed the system.
What: Threat Signals, a set of AI skills that polls a chosen RSS feed, converts new articles into markdown through Browser Run, stores the text in R2, extracts and normalizes indicators of compromise, summarizes each report, tags it using the account's existing tag catalog and records every indicator as a threat event linked to its source. Alongside it, the Threat Events Platform opens to all accounts for free, with one feed and up to 30 days of storage; paid enterprise tiers add feeds, proprietary datasets, custom skills, more storage and custom WAF rules. The post is inconsistent on whether free accounts can apply indicators to WAF policy.
When: Today, during Cloudflare's Birthday Week. Threat Signals is generally available now through the API and dashboard; further ingestion pipelines beyond RSS are planned without a date.
Where: In the Cloudflare dashboard under Application Security and Threat Intelligence, and through the API, with each account's data held in a private, account-scoped dataset.
Why: Cloudflare says converting unstructured research into indicators by hand strips out the context that explains them, and that customers found existing platforms could not scale beyond 100 feeds. For the marketing community, the release bears on malvertising and brand impersonation research, on indicators that point at cloud services marketing teams rely on, on the spread of skill files across ad tech, and on a year of cuts among security and infrastructure staff.
Discussion