Product1 distinct publisher3 min readPublished
The early-access service reads live traffic to work out which findings matter, then produces a scoped firewall rule and a draft patch for review, so the mitigation is what actually ships while the code fix waits on engineers.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
Each engagement begins with one application the customer nominates [17], and access is invitation only, held to selected enterprise customers, with no pricing disclosed and no date for anything wider [16][19]. So before a model runs, somebody has to name, to a vendor, the app they are least confident about. That upfront targeting step is the one a scanner never asks for.
What teams say about their vulnerability backlog is that it is a triage problem. What they do is put a mitigation in front of the vulnerable route and leave the code ticket open. Cloudflare has built the product around the second behaviour. The firewall rule is the thing that goes live, scoped to the method, path and request details needed to reach the vulnerable code, and the patch is a draft handed to engineers [7]. Both wait on explicit human approval, and Cloudflare says the models cannot apply either one by themselves [8].
The volume argument behind it holds up. Cloudflare cites 60,475 vulnerabilities taken into the National Vulnerability Database by September against 48,185 for all of 2025 [11]. Read as nine months, that is roughly 6,719 a month versus 4,015 a month last year, about 1.67 times the rate [12]. The real cleverness of the design sits downstream of that volume number. A finding is validated first, and its risk rating then moves up when production evidence shows heavy traffic or active probing against the affected route [5][6]. That is a re-ranking service wearing a discovery service's name, and re-ranking is what a team drowning in scanner output actually needs. Cloudflare's own framing of the gap is that scanners hand over thousands of findings without showing which ones matter in production [24].
On the word edge, some precision is owed. Prompts travel through Cloudflare AI Gateway to OpenAI servers, and no inference runs on Cloudflare's own network [9]. Enforcement happens at the edge; the reasoning happens in someone else's data centre, with redaction deciding how much request context travels [9]. Every proposal must also clear checks written outside the model, and a failed check ends the workflow before the customer sees anything [10]. That redaction step, and what it lets through before a request reaches OpenAI's servers, is the detail a security review needs to interrogate closely.
The capability figure deserves the same care. OpenAI reports GPT-5.6-Cyber completing 95% of advanced cybersecurity requests on its own benchmark against 1.5% for GPT-5.6 Sol [14], about 63 times as many [15]. That measures the model's willingness to attempt the work, a separate question from whether the fix it produces is correct. Palo Alto Networks put the same models into Unit 42 consulting engagements last month [20], which is the research-services shape of this capability. Cloudflare's version ends in a rule that blocks traffic.
For anyone weighing an invitation, the grid has two axes: whether the route has production evidence behind it, and whether you control the code. Evidence plus your code, take the rule as a bridge and ship the patch. Evidence plus code you do not control, a vendor library or a third-party route, and the rule is the permanent answer, which means it needs an owner and a review date in writing. No evidence but your code, and it stays in the queue where it already was. No evidence and no control, and you are looking at a scanner finding with a better paragraph attached.
Ranked by verification strength, evidence, and original report placement.
Cloudflare Inc. opened early access to Vulnerability Discovery and Remediation, a service that uses OpenAI cybersecurity models to find software flaws in customer applications and block attacks on them at the network edge.
The service runs inside Cloudflare Managed Defense, the company's security operations center offering, and reaches OpenAI's GPT-5.6-Cyber model through the Daybreak Defense Network.
Cloudflare first takes a snapshot from its Web Assets inventory and web application firewall showing which routes are live and what security events they have thrown off; code running on Cloudflare Workers is pulled in through Workers Observability.
A reconnaissance agent maps request paths to sections of the codebase, and hunter agents work from that map.
Every finding is validated before it gets a risk rating.
A finding's risk rating moves up if production evidence shows heavy traffic or active probing against the affected route.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Cloudflare joins code findings to live route traffic before GPT-5.6 Cyber writes the patch2 distinct publishers
product
OpenAI gates its first 'critical' cyber model behind an early-access partner list1 distinct publisher
build
OpenAI's August changelog cuts Sol prices and puts a date on them2 distinct publishers
leadership
Every notable AI release today arrived with a grade written by its own vendor1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single account, vendor-described throughout
One outlet carries this story, and inside it almost every mechanism — validation before rating, redaction, the outside-the-model checks — is Cloudflare describing its own pipeline with nothing checking it. The lone number sourced elsewhere, the National Vulnerability Database intake, arrives secondhand and sets a partial year against a full one without saying so. No customer, no precision figure, no independent look at a single finding.
Invitation-only pilot, one app at a time
The disclosed footprint is small enough to state in a sentence: selected enterprise customers, by invitation, each starting on a single nominated application, with no count and no price. What keeps this from the floor is the company Cloudflare is keeping — Palo Alto's Unit 42 was already running these models a month earlier and Proofpoint shipped a Daybreak-backed analyst agent the same day, so the model tier itself is being resold in several places even if nobody has said how many seats.
Frontier framing, pilot reality
Prince's line — hand-fought defense is losing, this stops attacks before they land — runs well ahead of an invitation-only trial whose two outputs both wait for a human to click approve. The 95%-against-1.5% spread measures request completion on an in-house benchmark, not bugs found in anyone's live application. The reporting itself pulls the other way in places, naming the approval gate and the missing price, which is why this sits short of the top of the scale.
Three sellers, one news day
The same day serves everyone in it. Cloudflare launches a new capability inside a paid security-operations offering, OpenAI advertises demand for its higher Daybreak Red tier while pledging $1 billion of subsidized access to utilities and small banks, and Proofpoint lands its own announcement in the slipstream. None of this is concealed — but every statement about how well the pipeline performs originates with a party that benefits if you believe it.
Clear on shape, blank on performance
What the service is, and what it refuses to do — no autonomous rule, no autonomous patch, no inference on Cloudflare's edge — is stated plainly enough to rely on. Everything about how well it works is a different matter: finding quality, review burden, and how often a stopgap rule blocks something legitimate are all unmeasured, in a product that is not generally available and has been described once.