Defend against frontier cyber models: Cloudflare's architecture as customer zero

2026-06-18T07:24:07Zeb1d8e3eddac16b5439e9f5779c9e0b78415b18dfa20c3a4990fd83a3e37fc08
Cloudforce OneLLM-securityWAFaccount-abuseai-security-for-appsapi-securitycf.intelclient-side-securitycloudflarecopy-failddosipseclinuxlog-explorermanaged-oauth','mcp','phishingmodel-riskpingorapingora-0.8.0post-quantumpqcryptoprivilege-escalationproject glasswingrequest-smugglingthreat-intelligencevulnerability-scanner

What happened

Collection of Cloudflare security posts (Mar–Jun 2026) covering: defenses for frontier/LLM-powered attacks (Project Glasswing, model risk and mitigation), real-time use of Cloudforce One threat intel in WAF via cf.intel fields, mitigation of a public Linux kernel privilege-escalation (“Copy Fail”) with no customer impact, GA post-quantum IPsec (hybrid ML-KEM) and a 2029 PQ roadmap, fixes for request-smuggling in Pingora OSS (Pingora 0.8.0), new Web/API vulnerability scanner, expanded Log Explorer datasets for multi-vector investigations, client-side security and AI Security for Apps GA, new OA

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
eb1d8e3eddac16b5439e9f5779c9e0b78415b18dfa20c3a4990fd83a3e37fc08
Enrichment time
2026-06-18T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.