Cloudflare Client-Side Security: smarter detection, now open to everyone

2026-04-03T19:24:07Z23bc2583c6ad0778d28c2eb765606fc33677574baa2ab23fea9cce447bfe7181
LLMaccount-abuseacmeai-securityapi-securitycertificate-validationcgnatclient-side-securitycloudflareddosfraud-preventiongraph-neural-networkslog-explorermerkle-tree-certificatesoptimistic-ackpingorapost-quantumquicrequest-smugglingvulnerability-scannerworkers-vpc

What happened

Cloudflare published a batch of security-focused updates: they opened advanced client-side security (using GNNs + LLMs) to all users, launched account-abuse/fraud prevention (Early Access), and made AI Security for Apps generally available. Operational/security tooling additions include multi-dataset Log Explorer investigation, a stateful Web/API vulnerability scanner, and Pingora OSS request-smuggling fixes in Pingora 0.8.0. They also disclosed mitigations for an ACME certificate-validation flaw, patched two QUIC acknowledgement-based DDoS vectors, and released a DDoS report documenting a 31.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
23bc2583c6ad0778d28c2eb765606fc33677574baa2ab23fea9cce447bfe7181
Enrichment time
2026-04-03T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.