Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-14T19:24:07Za4970da43e3d11da7b57a08ee43671c32f788daa0ff1acfcc4ce08aeb886a003
ACME validationAI Security for AppsAPI tokensCGNATDDoSLog ExplorerOAuthPingoraRFC 9728Workers VPCaccount-abuse protectionclient-side securityleast-privilegemanaged OAuthpost-quantum roadmaprequest smugglingresource-scoped permissionsscannable API tokensshadow AIshadow MCPvulnerability scanner

What happened

Cloudflare published a collection of security-focused announcements and disclosures covering API and developer identity controls, OAuth/managed OAuth improvements, a GA for resource-scoped permissions, and new defenses for AI and client-side threats. Notable items include fixes for request-smuggling vulnerabilities in the open-source Pingora ingress (Pingora 0.8.0), mitigation of an ACME certificate-validation logic issue, a post-quantum roadmap accelerated to 2029, GA of AI Security for Apps and Client-Side Security tools, a new Web/API vulnerability scanner, Log Explorer dataset expansions,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
a4970da43e3d11da7b57a08ee43671c32f788daa0ff1acfcc4ce08aeb886a003
Enrichment time
2026-04-14T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.