Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-26T07:24:05Z•1ca6779074f1a6c4f3f4f86339a5fbed5c55e60dc4f8312e65aa459851efca74
account-abuseacmeai-securityapi-tokensclient-side-securitycloudflareddosleast-privilegelog-explorermanaged-oauthoauthpingorapost-quantumpq-cryptoradarrequest-smugglingvulnerability-scannerworkers-vpc
What happened
Collection of Cloudflare security announcements (Mar–Apr 2026) covering developer and enterprise protections, threat trends, and vulnerability disclosures. Key items: scannable API tokens, enhanced OAuth visibility, and GA resource-scoped permissions to enforce least-privilege; Managed OAuth for Access (RFC 9728) to safely enable agent access; Cloudflare moved its target for full post‑quantum hardening to 2029; Client‑Side Security tooling opened broadly; Account Abuse Protection and AI Security for Apps reached Early Access/GA; new stateful Web & API vulnerability scanner and Log Explorer/enh
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 1ca6779074f1a6c4f3f4f86339a5fbed5c55e60dc4f8312e65aa459851efca74
- Enrichment time
- 2026-04-26T07:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.