Full Report
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.
Analysis Summary
# Industry News: Cloudflare Launches Threat Signals and Democratizes Cloudforce One Threat Intelligence
## Summary
Cloudflare has announced the general availability of Threat Signals, an innovative tool that uses AI-driven agentic skills to automatically ingest, parse, and extract structured indicators from unstructured, open-source threat reporting. Simultaneously, the company is expanding access to its core Cloudforce One Threat Events Platform, making both capabilities free to every Cloudflare account. This launch aims to allow organizations to automate and scale threat intelligence processes that previously required intensive manual human analysis.
## Key Details
- **Date:** September 29, 2026
- **Companies Involved:** Cloudflare (Cloudforce One)
- **Category:** Product Launch / Service Expansion
## The Story
During its "Birthday Week" initiatives, Cloudflare introduced Threat Signals to solve a long-standing challenge for security teams: the scaling of unstructured threat intelligence. While structured threat feeds are easily automated, valuable research published via RSS feeds, blogs, and open-source reporting requires human analysts to read, summarize, normalize indicators of compromise (IoCs), and tag contexts before applying them to defensive tools.
Threat Signals leverages AI "agentic skills"—rich, pre-programmed analytical instructions—to automate this workflow privately and securely within each customer's account dataset. The system continuously polls user-selected RSS feeds, translates unstructured text into structured "Threat Events," and enables security teams to directly link this newly surfaced context to active Web Application Firewall (WAF) rules.
To maximize the impact of this launch, Cloudflare is democratizing its broader threat intelligence ecosystem. Every Cloudflare account now receives free API and dashboard access to the Threat Events Platform and Threat Signals (limited to one custom RSS feed and 30 days of storage). Enterprise tiers (Essentials, Advantage, and Elite) can unlock advanced features, including custom agentic skills, infinite RSS feed scaling, higher storage retention, and integration with Cloudforce One’s proprietary threat intelligence datasets.
## Business Impact
### For the Companies Involved
- **Cloudflare:** Solidifies its transformation from a content delivery network (CDN) and basic infrastructure provider into a sophisticated enterprise security vendor. By offering a free tier, Cloudflare establishes a massive funnel to upsell accounts to paid enterprise threat intelligence tiers.
### For Competitors
- **Legacy Threat Intelligence Platforms (TIPs):** Traditional TIP vendors (such as ThreatConnect, Anomali, or Recorded Future) face aggressive pressure. Cloudflare is lowering the financial barrier to advanced intelligence workflows, making baseline TIP capabilities a commoditized feature.
### For Customers
- **End Users:** Security operations centers (SOCs) can now automate tedious open-source research compilation at no additional cost. This saves significant analyst hours, improves response times to emerging zero-days, and bridges the skills gap for smaller organizations without dedicated threat hunt teams.
### For the Market
- **The Market:** Signals a shift toward "Agentic Cybersecurity," where AI is used not just for static detection or basic chat queries, but as an autonomous agent performing discrete workflows mimicking experienced human practitioners.
## Technical Implications
Threat Signals shifts AI usage from generic LLM text generation to precise technical workflows. The engine normalizes disparate IoC formats, preserves lineage by linking parsed data back to the original source, and addresses AI hallucinations by enforcing rigid constraints. Notably, the AI's tagging capability is strictly limited to the user’s pre-existing, localized tag taxonomy to avoid semantic confusion. The architecture integrates seamlessly with Cloudflare's existing edge network, enabling immediate synchronization with WAF logic.
## Strategic Analysis
- **Market Positioning:** Cloudflare positions itself as an "infinitely scalable" operational layer for security teams. By integrating threat intelligence directly into its edge network infrastructure, it eliminates the middleware friction commonly associated with exporting intelligence into external security controls.
- **Competitive Advantage:** Direct execution. Unlike standalone intelligence platforms, Cloudflare can instantly convert an extracted threat signal into a network block rule across its global edge network.
- **Challenges:** Enterprise adoption will rely heavily on trust. If the AI agent incorrectly parses indicators or misattributes data, it could lead to false positives and block legitimate traffic, requiring robust administrative safeguards.
## Industry Reactions
- **Analyst Opinions:** Market analysts view this as a logical evolution of Cloudflare’s " Birthday Week" history of disruptive market democratization.
- **Expert Commentary:** Practitioners note that the focus on keeping the original source links and tracking whether a tag was applied automatically or by an analyst is a critical step in building trust in automated AI systems.
## Future Outlook
Cloudflare has indicated that RSS feeds are merely the initial data pipeline for Threat Signals. Future updates will expand the platform's ingest capabilities to support other formats, such as email pipelines, community threat slacks, and PDF research reports. The industry can expect fast-following moves from competitors attempting to embed similar agentic workflow automation into their security stacks.
## For Security Professionals
For CISOs and security practitioners, this release offers an immediate opportunity to enhance threat intelligence capabilities without additional budget overhead. Security teams should leverage the free tier to connect high-value open-source feeds (e.g., CISA alerts, specific cybersecurity research publications) and test the accuracy of the automated WAF rule generation, treating the AI agent as a digital analyst assistant to augment existing operational capacity.