AI NewsInfrastructureAnnouncement

Cloudflare launches Threat Signals, a free service that turns an RSS feed of security reports into WAF rules

Cloudflare turned on Threat Signals for every account on 29 September, a free service that reads a security RSS feed, pulls indicators of compromise out of each article, and hands them to the WAF policy editor.

AI News

Editorial2 min read

LinkedInX
Cloudflare Threat Signals dashboard showing summarised threat report with extracted indicators of compromise

Image: Cloudflare

Why it mattersA small security team that today reads threat reports by hand and copies indicators into WAF rules can now let one RSS feed do that job automatically, without buying a threat-intelligence subscription.

A small security team reading threat reports by hand and copying the IPs and hashes into a firewall rule has always had a job that a script could do. Cloudflare's Threat Signals, published on 29 September by Emilia Yoffie and Victor Niño, is that script, and it is free on every account.

What Threat Signals does

Point Threat Signals at a security RSS feed and it polls the feed on a schedule. For each new article it fetches the page through Browser Run's Markdown quick action, stores the cleaned text in R2, and passes it through an IOC extractor and a set of Cloudforce One skills that summarise the article, tag it, and pull out each indicator of compromise. Cloudflare says "the end result is a contextualized indicator stored in your account's private Threat Intelligence dataset", searchable from the dashboard or the API and linked back to the report it came from.

The point of the linkage is that an indicator without its source is just a string. An IP address flagged by three different feeds for three different reasons needs the three original reports to judge whether to block it, or whether to only rate-limit certain paths on it. Threat Signals keeps that trail attached.

What you get free, and what the tiers add

Every Cloudflare account, including free ones, gets API and dashboard access, one RSS feed of its own choice, a private dataset with 30 days of storage, and access to the Threat Events Platform to investigate the indicators and tags coming out of that feed. Cloudflare says the service is generally available today.

The Enterprise tiers (Essentials, Advantage, Elite) raise the feed count, unlock Cloudforce One's own proprietary threat intelligence datasets, and let a team generate custom agentic skills and higher-storage datasets. The paid tiers also add the ability to turn events into custom WAF rules directly, which is how the loop closes from a threat report published this morning to a live rule this afternoon.

What it changes for a small team

Threat Signals does not replace a dedicated threat intelligence team. It reduces the manual step between reading a security disclosure and applying its contents to a policy, so a two-person security function can keep up with more feeds than it could by hand and still hold the reasoning behind every rule it writes. A team already paying for a commercial IOC feed can compare that feed's output side-by-side with Threat Signals reading the same source, and decide whether the paid subscription is doing enough extra work to justify itself.

Threat Signals sits on top of Browser Run for fetching, R2 for storage and the Cloudforce One skills library for the summarisation and IOC work, so the free tier gives every account a working piece of Cloudflare's own security pipeline rather than a demo. What the paid tiers add is width (more feeds, proprietary datasets) and the ability to push directly into the WAF, which is what a security team would actually pay for.

Source

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX