Cloudflare Client-Side Security: smarter detection, now open to everyone

2026-04-04T19:24:07Z5731c8c9b2aa4df347d39f2c0377ce0991424317cb704978b62dd3b0008eb6ea
account-abuse-fraud-preventionacme-validationai-securityapi-vulnerability-scannercgnat-detectionclient-side-securityddosgraph-neural-networkllmlog-explorermatrix-homeservermerkle-tree-certificatesphishing-detectionpingorapost-quantumquicrequest-smugglingworkers-vpc

What happened

Collection of Cloudflare blog posts (late 2025–Mar 2026) covering new and updated security products, threat research, and vulnerability disclosures. Key highlights: Client‑Side Security (cascading AI detection using GNNs + LLMs) opened to all; Account Abuse Protection and AI Security for Apps announcements; a new Web & API vulnerability scanner; Log Explorer enhancements for multi‑vector attacks; disclosure and fix for request smuggling in Pingora OSS (fixed in Pingora 0.8.0); mitigation of an ACME validation logic issue; patches for QUIC acknowledgement‑based DDoS vectors; a 31.4 Tbps DDoS in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
5731c8c9b2aa4df347d39f2c0377ce0991424317cb704978b62dd3b0008eb6ea
Enrichment time
2026-04-04T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.