Cloudflare launched Threat Signals for every account on September 29, 2026. It reads a selected security-report RSS feed, summarizes reports, and extracts indicators such as suspicious IP addresses or domains. RSS is a machine-readable list of a site’s new posts. Each derived threat event retains a link to the original report, letting an analyst inspect why an indicator appeared. Source
What the free access includes
Every account can choose one RSS feed and use the dashboard and API. Cloudflare says the account-private dataset derived from that feed is retained for up to 30 days. The Threat Events Platform can be used to examine the account’s events, indicators, and tags. More feeds, longer storage, and custom agentic skills are described as enterprise options. Source
From a report to a rule
The system connects the extracted indicator to the source report and its context. A WAF, or web application firewall, applies rules to incoming web requests. Operators can investigate a threat event and use relevant indicators in WAF policies. Cloudflare gives Application Security → Threat Intelligence → Threat Signals as the dashboard path for adding the first RSS feed. Source