Trusence Every claim has a source
Last updated 7 October 2026 Search Türkçe
← All stories
Security

Cloudflare hardens its WAF after AI-driven stress tests

The tests turned up a small set of actionable flaws, prompting new detections and a rule update in Cloudflare’s Managed Ruleset.

Cloudflare used frontier AI models inside a controlled harness to stress-test its Web Application Firewall, and the exercise led to three updates in its Managed Ruleset. The run covered 45 scenarios and 1,107 mutation attempts, with human review narrowing the output to 49 findings; 48 of those involved command injection or server-side request forgery. The models worked without access to Cloudflare’s WAF rules, source code, or internal security signals, while a Python harness handled request replay, scenario state, limits, and response collection. Cloudflare says the work added two new detections, SSRF - Obfuscated Host and SSRF - Restricted Protocol, plus an improvement to the existing SSRF - Cloud rule.

Why it matters

For users of Cloudflare’s WAF, the point is that the company is using AI to find weaknesses before attackers do. The exercise produced a narrow set of findings from a much larger test run, and Cloudflare says it has already turned those results into three rule changes. That means the service is being updated based on live probing rather than only on manual review.

Sources

  • InfoQ