Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-15T07:24:08Z•4e4ed4d386fdf8c34c06c587a82aa48038e7750672c0d80ddacfb11c6673381f
ACME validation vulnerabilityAI Security for AppsAI discoveryAPI tokensAccount abuse protectionCloudflareDDoSGNNLLMLog ExplorerManaged OAuthOAuthPingoraPingora 0.8.0RFC 9728Web and API vulnerability scannerWorkers VPC Services','CGNAT','Matrix homeserver','ASPA','Key-透明client-side securityleast privilegepost-quantum 2029post-quantum roadmaprequest smugglingresource-scoped permissionstoken revocationvulnerability disclosure
What happened
Cloudflare published a batch of security-focused announcements and disclosures. Key themes: improved developer credential hygiene (scannable API tokens, automated revocation, resource-scoped permissions GA, recommendations for least-privilege and token cost reduction), Managed OAuth for Access (RFC 9728 support to enable agent-safe auth), expanded AI security and discovery (AI Security for Apps GA, Client-Side Security public, Cloudy LLM explanations, free AI discovery for shadow AI), new detection and defender tooling (Web & API vulnerability scanner, Log Explorer multi-dataset investigations
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- 4e4ed4d386fdf8c34c06c587a82aa48038e7750672c0d80ddacfb11c6673381f
- Enrichment time
- 2026-04-15T07:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.