Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-21T19:24:10Z•12e7100ec6103366b0dcb94830c4a8483319a4eb320a8f8325791e525bac8d0d
LLMPQ-2029RFC-9728account-abuse-protectionacme-validationacquisitionai-securityapi-securityapi-tokenscgna-detectionclient-side-securitycloudflareddosgraph-neural-networkslog-explorermanaged-oauthmulti-vector-attacksoauthpingorapost-quantumradarrequest-smugglingscoped-permissionsvulnerability-scannerworkers-vpc
What happened
Collection of Cloudflare security updates (Apr 2026 and prior) announcing multiple product launches, security features, and incident reports: scannable API tokens and resource-scoped permissions for least-privilege; Managed OAuth for Access and RFC 9728 support; GA of AI Security for Apps and expanded client-side security (GNN + LLM); Account Abuse Protection and Log Explorer enhancements for multi-vector investigations; disclosure and fixes for request smuggling in Pingora OSS (fixed in Pingora 0.8.0) and mitigation for an ACME validation logic vulnerability; a new Web/API vulnerability (API)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 12e7100ec6103366b0dcb94830c4a8483319a4eb320a8f8325791e525bac8d0d
- Enrichment time
- 2026-04-21T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.