
Cloudflare launches Threat Signals, free open-source threat intelligence for every account
Cloudflare has launched Threat Signals, a service that automatically turns open-source threat reporting into contextualized indicators of compromise that can be applied directly in WAF policies. It is free for every Cloudflare account via API and dashboard.
Cloudflare has introduced Threat Signals, a service that automatically processes open-source threat reporting and turns it into intelligence security teams can act on. It is free for every Cloudflare account via API and dashboard, the company says.
What Threat Signals does
Threat Signals takes open-source reporting chosen by the user and runs a set of agentic skills over it. A skill is a detailed instruction set that captures how an experienced analyst handles one part of the job. The skills summarize each report, surface key context, extract and normalize indicators of compromise (IOCs) and apply tags inside a private, account-scoped dataset.
The result is a contextualized indicator stored in the account's private Threat Intelligence dataset as a Threat Event, ready to be applied in a WAF policy. Cloudflare is also making Cloudforce One's Threat Events Platform free for every account: each account can select one RSS feed, gets a private dataset from that feed stored for up to 30 days, and access to investigate events, indicators and tags.
How it works
Feeds are monitored over RSS, with support for RSS 2.0, Atom and RSS 1.0/RDF. Each selected feed enters a Cloudflare Workflow that periodically polls for new articles; Browser Run's Markdown quick action cleans the article text into readable markdown, stored in R2. The text then passes into an IOC extractor and default Cloudforce One skills that summarize it, apply tags and add context at the indicator level.
The output is a concise summary and key points answering what happened, who was affected and why the report matters. Every indicator is backed by a threat event in the account's own dataset, so the event, its indicators, its tags and the original report stay connected and traceable.
What Cloudflare learned
The first version was a one-week internal prototype built by a threat analyst. Making it reliable was harder than parsing the data. Cloudflare limited AI tagging to each account's existing tag catalog and recorded whether each tag was applied automatically or by an analyst, which made automatic tagging easier to trust. The feature analysts kept returning to was the link between an event and its source report.
Availability
Threat Signals is generally available for every Cloudflare account via API and the dashboard. Feeds are configured under Application Security, Threat Intelligence, Threat Signals. Open-source reporting is not limited to RSS, and Cloudflare says more ingestion pipelines are next.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.