Cloudflare Client-Side Security: smarter detection, now open to everyone

2026-04-04T07:24:06Z1f1dc6d019ddcf462f07c62044ce3e3bb0338bfed6aec3ca49cb7ad5f736ef72
ACMEAI-for-appsAI-securityAPI-securityCGNATDDoSLLMLog ExplorerMerkle Tree CertificatesPingoraQUICWorkers VPCaccount-abusecertificate-validationclient-side securitycloudflareemail-securityfraud-preventiongraph neural networkphishingpost-quantumrequest-smugglingvulnerability-disclosurevulnerability-scannerzero-day detection

What happened

Collection of Cloudflare blog posts (late 2025–Mar 2026) announcing expanded security capabilities and several disclosed/fixed vulnerabilities. Highlights include: public rollout of advanced Client‑Side Security using GNNs + LLMs to reduce false positives and catch zero‑days; new Account Abuse Protection and AI Security for Apps; an AI‑driven Web & API vulnerability scanner; Log Explorer improvements for multi‑vector forensics; and disclosures/fixes for request smuggling in Pingora OSS (fixed in Pingora 0.8.0), an ACME certificate‑validation logic issue (mitigations described), and two QUIC‑aw

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
1f1dc6d019ddcf462f07c62044ce3e3bb0338bfed6aec3ca49cb7ad5f736ef72
Enrichment time
2026-04-04T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cloudflare Client-Side Security: smarter detection, now open to everyone · Baitaphish