Securing non-human identities: automated revocation, OAuth, and scoped permissions

2026-04-19T07:24:04Zf2ea77a128437fc760082b069737ae7a606e1497c2c83561cf9c14dbbf12d005
ACME validationACME vulnerabilityAI securityAPI tokensAccount abuse protectionCloudflareDDoS reportGNNLLMLog ExplorerMCPManaged OAuthMatrix homeserver PoCOAuthPQCPingoraPingora 0.8.0RFC 9728Workers VPCclient-side securityleast-privilegepost-quantumrequest smugglingscoped permissionsvulnerability scanner

What happened

A Cloudflare security blog feed summarizing multiple product security updates and research (April 2025–2026). Key items include scannable API tokens, enhanced OAuth visibility, and GA resource-scoped permissions to enforce least-privilege; Managed OAuth for Access (RFC 9728) for agent-ready internal app access; and moves toward full post-quantum readiness by 2029. Cloudflare also announced GA of AI Security for Apps, client-side security tooling (GNN+LLM detections), Account Abuse Protection in Early Access, a new Web/API vulnerability scanner, Log Explorer enhancements for multi-vector attack

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cloudflare_security_blog
Record identifier
f2ea77a128437fc760082b069737ae7a606e1497c2c83561cf9c14dbbf12d005
Enrichment time
2026-04-19T07:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Securing non-human identities: automated revocation, OAuth, and scoped permissions · Baitaphish