Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-26T07:24:05Z1ca6779074f1a6c4f3f4f86339a5fbed5c55e60dc4f8312e65aa459851efca74
account-abuseacmeai-securityapi-tokensclient-side-securitycloudflareddosleast-privilegelog-explorermanaged-oauthoauthpingorapost-quantumpq-cryptoradarrequest-smugglingvulnerability-scannerworkers-vpc

What happened

Collection of Cloudflare security announcements (Mar–Apr 2026) covering developer and enterprise protections, threat trends, and vulnerability disclosures. Key items: scannable API tokens, enhanced OAuth visibility, and GA resource-scoped permissions to enforce least-privilege; Managed OAuth for Access (RFC 9728) to safely enable agent access; Cloudflare moved its target for full post‑quantum hardening to 2029; Client‑Side Security tooling opened broadly; Account Abuse Protection and AI Security for Apps reached Early Access/GA; new stateful Web & API vulnerability scanner and Log Explorer/enh

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
1ca6779074f1a6c4f3f4f86339a5fbed5c55e60dc4f8312e65aa459851efca74
Enrichment time
2026-04-26T07:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.