Tech news, developer blogs and social updates in one fast feed
We tested our own WAF with frontier AI models. Here’s what we found
We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an authorized staging environment and discovered detection gaps worth fixing. Here’s how the loop worked, what got through, and what we did about it.
Cloudflare tested its WAF with frontier AI models, simulating attacks to see how well it blocked them, and found that the WAF blocked most attempts.
Cloudflare built a system to test its WAF with frontier AI models, simulating attacks without accessing WAF internal information.
The system iterated over multiple scenarios, choosing different attack categories and variations.
The WAF blocked most attempts, with 1,107 attempts made and 44 scenarios run across six attack categories.
The WAF was configured with WAF Attack Score blocking scores of 30 or below and all Cloudflare Managed Ruleset enabled.
Summarised automatically by AI from the original article by The Cloudflare Blog. AI can make mistakes, so check the original for details.
“Is your WAF ready for frontier AI models?” We keep hearing this question from our customers, so we decided to find out.
When it comes to exploiting applications, what LLMs are really good at is iterating and mutating attack payloads faster than any human hacker could do. LLMs can use real-time responses to iterate and change their techniques by, for example, testing different encodings, sending the payload in a different part of the HTTP request, or moving to the next vulnerability to test.
Even before LLMs were around, security engineers used two common approaches to test applications: static and dynamic application security testing. The former analyzes code without executing it to identify vulnerabilities, while the latter probes running applications to find runtime flaws. There are plenty of works scanning code with frontier AI models, including details on how to build your own harness.
Read the full story on The Cloudflare BlogThat's the opening of the story. The full piece is published by The Cloudflare Blog.
This week, Cloudflare's Impact programs will reach $100 million in donated services. It's a significant milestone, and one that we are proud of because it means that thousands of…
From our conversations with companies at every stage of their AI adoption journey, we've seen some common patterns. First, there is an exploration period as you bring on every…
As agents help us build more complex applications, both humans and agents need a better way to stay on top of what goes wrong in production. Coding agents can already query…
You just thought of your next great idea, and buying the right domain feels like the easiest way to make that first bit of progress. Naturally, you open a new tab in your…
Today, we’re making the Cloudflare Monetization Gateway available as part of a closed beta, and showcasing four customer use cases that are in production today. Since we…
AI answer engines read a publisher’s page and hand the reader a summary, so the visit, and the revenue that would come with it, never happens. Most publishers will never sign a…
Misty mornings, leaves shining in bright red, yellow, and orange hues, and spooky creatures making an appearance — October has a very special charm. So, how about some new…
Policy decisions increasingly shape how developers build, collaborate, and participate in open source. That makes it important not only to be transparent about how GitHub…