Securing non-human identities: automated revocation, OAuth, and scoped permissions
2026-04-19T07:24:04Z•f2ea77a128437fc760082b069737ae7a606e1497c2c83561cf9c14dbbf12d005
ACME validationACME vulnerabilityAI securityAPI tokensAccount abuse protectionCloudflareDDoS reportGNNLLMLog ExplorerMCPManaged OAuthMatrix homeserver PoCOAuthPQCPingoraPingora 0.8.0RFC 9728Workers VPCclient-side securityleast-privilegepost-quantumrequest smugglingscoped permissionsvulnerability scanner
What happened
A Cloudflare security blog feed summarizing multiple product security updates and research (April 2025–2026). Key items include scannable API tokens, enhanced OAuth visibility, and GA resource-scoped permissions to enforce least-privilege; Managed OAuth for Access (RFC 9728) for agent-ready internal app access; and moves toward full post-quantum readiness by 2029. Cloudflare also announced GA of AI Security for Apps, client-side security tooling (GNN+LLM detections), Account Abuse Protection in Early Access, a new Web/API vulnerability scanner, Log Explorer enhancements for multi-vector attack
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cloudflare_security_blog
- Record identifier
- f2ea77a128437fc760082b069737ae7a606e1497c2c83561cf9c14dbbf12d005
- Enrichment time
- 2026-04-19T07:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.