VYPR
advisoryPublished Sep 29, 2026· 1 source

Cloudflare Launches Threat Signals to Automate Open-Source Threat Intelligence Analysis

Cloudflare introduces Threat Signals, an AI-powered service that automates the summarization and extraction of actionable intelligence from open-source threat reports for all account holders.

Cloudflare has launched Threat Signals, a new AI-driven service designed to automate the analysis of open-source threat intelligence reports. This tool aims to bridge the gap between raw research findings and actionable security measures, enabling organizations to scale their threat intelligence capabilities akin to how they scale infrastructure.

Traditionally, security teams have automated the ingestion of structured threat feeds, but processing unstructured reports from sources like research blogs has remained a significant manual challenge. Threat Signals addresses this by employing "agentic skills" – sets of detailed instructions that mimic how experienced analysts process information. These skills automate the summarization of reports, extraction of key context, normalization of indicators of compromise (IOCs), and application of relevant tags, all within a private, account-scoped dataset.

The service is made available to every Cloudflare account, offering API and dashboard access to Threat Signals along with the ability to select one RSS feed. The extracted intelligence is stored as a "Threat Event" in a private Threat Intelligence dataset, which can then be directly applied to Cloudflare's Web Application Firewall (WAF) policies for immediate protection.

For enterprise customers on Essentials, Advantage, and Elite plans, Cloudflare offers expanded capabilities. These include support for more RSS feeds, access to Cloudforce One's proprietary threat intelligence datasets, the ability to generate custom agentic skills, increased storage for derived reporting, and the option to create custom WAF rules based on both open-source and proprietary threat events.

Cloudflare's decision to focus initially on open-source intelligence stems from its widespread impact and the challenges in scaling its analysis. The platform supports RSS 2.0, Atom, and RSS 1.0/RDF feed specifications. Once a feed is added, a workflow periodically polls for new articles, cleans the text, and passes it to an IOC extractor and a set of default skills.

The output provides concise summaries and key points, allowing analysts to quickly grasp the essence of a report, identify affected parties, and understand its significance. Crucially, each extracted indicator is linked back to its originating threat event and report within the private dataset, ensuring traceability and context.

Cloudflare emphasizes that the difficulty in building Threat Signals lay not just in parsing data, but in ensuring the output was trustworthy and genuinely useful to analysts. The company learned that unfamiliar vocabulary or poorly contextualized intelligence hinders adoption, leading them to prioritize familiar taxonomies and clear links between indicators and their source reports.

This initiative represents a significant step towards making sophisticated threat intelligence more accessible and actionable, particularly for organizations that may lack dedicated, large-scale threat analysis teams. By automating the laborious process of turning research into defense, Cloudflare aims to empower a broader range of users to proactively defend against evolving cyber threats.

Synthesized by Vypr AI
Cloudflare Launches Threat Signals to Automate Open-Source Threat Intelligence Analysis · VYPR