Skip to main content
SecuritySeptember 30, 20262 min read

Cloudflare Makes Threat Intelligence Free for Every Account

Get technical support

Which of these can actually be exploited?

Cloudflare now gives every account Threat Signals, which turns a security RSS feed into tagged indicators, plus access to its Threat Events platform. The free tier covers one feed and 30 days of data, and turning indicators into WAF rules stays on enterprise plans.

What Cloudflare Announced

On September 29, 2026, during its Birthday Week, Cloudflare launched Threat Signals and opened its Threat Events platform, the core of its Cloudforce One threat intelligence offering, to every Cloudflare account at no charge.

Threat Signals reads security reporting from RSS feeds you choose, in RSS 2.0, Atom or RSS 1.0 format. It fetches each new article and runs it through a set of AI skills that summarize the report, pull out indicators of compromise such as IP addresses and domains, normalize them and tag them with your account's own tag catalog. Each indicator is stored as a threat event in a private dataset in your account, still linked to the report it came from, so a year later someone can see why an address was flagged.

What the Free Tier Includes

Every account now gets:

  • dashboard and API access to Threat Signals, with one RSS feed
  • a private dataset built from that feed, kept for up to 30 days
  • dashboard and API access to the Threat Events platform, to investigate the events, indicators and tags in that dataset

The setup is in the Cloudflare dashboard under Application Security, then Threat Intelligence, then Threat Signals.

What Stays on Enterprise Plans

The announcement describes indicators that can go straight into a WAF policy, but the list of what every account gets does not include that step. Creating custom WAF rules from threat events belongs to the Essentials, Advantage and Elite enterprise tiers, together with more feeds, Cloudflare's own proprietary datasets, custom skills and longer storage. The feature that builds a WAF rule from a saved view of threat events was released in June for Cloudforce One customers, and Cloudflare's product documentation still describes Cloudforce One as a subscription.

So on the free tier, Threat Signals is a tool for reading and research. It does not block anything by itself.

Who Gets Something From It

A team that already follows a few security sources gets summaries and extracted indicators without copying them by hand. With a single feed, choose the one that matters most to you, such as your national CERT or the security advisories of the platform you run. When a report names addresses or domains, the extracted list is ready to search for in your own logs.

For a typical store or company site, the practical value is modest. One feed and 30 days of data make a useful reading list, not a defense, and patching quickly still does more than any indicator list. Deciding which reports actually matter to you is the harder skill, and our guide to reading a CVE in ten minutes covers it. Building that routine around your own stack is part of Security & Compliance.

Sources

Or read how we handle it in Security & Compliance.

Related News

Security

The New cPanel Critical Bug Needs a Valid Login and Still Outscores April's Unauthenticated Root Flaw

CVE-2026-58048, published July 31, 2026, is a 9.4 critical privilege escalation in cPanel and WHM: renaming a database fails to preserve SQL mode, so a customer's SQL executes in root context. It requires a valid cPanel account and the MySQL feature, which sounds reassuring until you compare the scores. April's unauthenticated authentication bypass rated 9.3. This one needs a login and rates 9.4, and the entire difference lives in the CVSS 4.0 subsequent-system metrics: the CNA scored this as breaking out of the account and taking the host with it. On a shared server that means any tenant, including one who paid for a month. Covers the exact first-fixed builds per release tier, the quieter companion CVE, and why automatic updates are the answer to a different question.

Security

OpenSSL 3.0 Stops Getting Security Fixes in September and You Probably Still Ship It

OpenSSL 3.0 stops receiving all fixes, including security fixes, after September 7, 2026, and the 3.4 line follows on October 22. For most teams the distro backports cover it, but self-compiled, vendored, and container-bundled OpenSSL go quietly unpatched. Here is who is actually exposed and how to check.

Security

The New libssh2 SSH Flaw Is Client-Side, Not Your sshd, and apt upgrade Will Not Fix the Copies That Matter

CVE-2026-55200 is an out-of-bounds write in the libssh2 client library that a malicious or compromised SSH server can use to corrupt a connecting client's memory, and a public proof-of-concept is already out. The corrections that matter: it is client-side and not an OpenSSH or sshd bug, the severity rating is disputed across scorers, and the real cleanup is finding the statically linked and vendored copies a distribution update never touches.