October 2026 Summaries
27 posts from Cloudflare
Filter
Month:
Year:
Post Summaries
Back to Blog
No summary generated yet.
Oct 09, 2026
1,689 words in the original blog post.
No summary generated yet.
Oct 09, 2026
1,751 words in the original blog post.
No summary generated yet.
Oct 09, 2026
1,933 words in the original blog post.
No summary generated yet.
Oct 08, 2026
981 words in the original blog post.
Cloudflare describes a multi-agent AI system for its Managed Defense service designed to reduce the workload of security analysts handling large volumes of related alerts. Rather than relying on a single general-purpose model, the system first uses deterministic reconnaissance workflows to collect versioned, scoped evidence on customer activity, detections, enforcement outcomes, historical decisions, and network observations, then filters likely false positives with Cloudflare’s Clef decision model. Alerts requiring further review are evaluated in parallel by specialized agents focused on traffic behavior, customer history, privacy-preserving global telemetry, and admitted threat intelligence, with a separate synthesis agent producing an advisory constrained by validated evidence and approved classifications. The platform records missing or unavailable data explicitly, validates citations and customer boundaries in application code, and allows analysts to inspect, revise, or act on recommendations such as rate limits, WAF rules, or DDoS protection changes. Cloudflare says human Managed Defense Analysts retain responsibility for final decisions, while the early beta is available for eligible application-security alerts and cases, with plans for more customizable and continuous monitoring capabilities.
Oct 07, 2026
1,842 words in the original blog post.
On October 11, 2026, the DNS root’s key-signing key will change from KSK-2017 to KSK-2024, only the second such rollover and a critical event for DNSSEC, which authenticates DNS responses through a chain of cryptographic trust rooted in this key. DNSSEC-validating resolvers must trust KSK-2024, identified by key tag 38696, before the change or they could make otherwise functioning websites across all top-level domains unreachable; most website operators and users of Cloudflare DNS, 1.1.1.1, or Gateway DNS require no action. Resolvers can learn the new key automatically under RFC 5011 after observing it consistently for at least 30 days, and KSK-2024 has been published since January 2025, while Cloudflare also embedded it in its software trust anchors to reduce risks associated with upgrades or lost resolver state. Cloudflare’s readiness test uses the RFC 8509 trust-anchor sentinel protocol to determine whether a browser’s resolver recognizes the new key, although unsupported sentinel queries produce inconclusive rather than negative results. The rollover retains the RSA/SHA-256 algorithm but helps test the operational process of distributing and retiring trust anchors, with KSK-2017 scheduled for revocation and removal in 2027; it also provides preparation for possible future transitions to ECDSA and eventually post-quantum DNSSEC cryptography.
Oct 06, 2026
2,016 words in the original blog post.
Cloudflare’s 2026 Birthday Week marked its 16th anniversary with 46 announcements focused on adapting Internet infrastructure to AI-driven traffic, automated agents, emerging security risks, and expanding developer needs. The company emphasized open source through its new cf command-line interface, Forge generation pipeline, EmDash CMS, and investments in JavaScript, Rust, browser, and web-performance tools. Security updates included plans to become a public certificate authority, support for post-quantum cryptography and visibility, AI-assisted cryptography discovery, stronger IPsec protections, and adaptive application-security capabilities. Cloudflare also introduced tools intended to support an agent economy, including pay-per-use content access, an HTTP 402-based Monetization Gateway, improved containers and AI routing, and expanded domain management. Developer-platform additions included the general availability of the Basin data platform, K2 serverless event streams, faster Workers KV, AI Search, agent workspaces, and open-source decision models. The final announcements expanded observability, request tracing, privacy infrastructure, account-abuse investigation, authenticated tunnels, web search for AI applications, and network performance, while highlighting contributions from its intern program and continued support for civil society organizations.
Oct 05, 2026
2,066 words in the original blog post.
Cloudflare reports progress toward its goal of hiring up to 1,111 interns in 2026, having hosted 750 internships across 48 teams and nine global offices while continuing recruitment. The company argues that AI tools can help early-career employees learn unfamiliar systems, prototype solutions, and automate routine work more quickly, while managers and mentors retain responsibility for direction, review, and quality. Interns contributed across engineering, product management, audit, customer support, and people operations, delivering projects such as cache compression technology, improvements to the EmDash content management system, post-quantum cryptography visibility tools, AI-assisted compliance workflows, and research on Internet routing practices. Several intern contributions were included in Cloudflare Birthday Week launches, and the program also emphasized community-building, executive access, and mentorship. Cloudflare plans to expand the initiative, study how interns work effectively with AI, and convert many participants into full-time employees.
Oct 05, 2026
1,058 words in the original blog post.
Cloudflare has introduced a Web Search API through AI Gateway, partnering initially with Ceramic.ai, Exa, and Linkup to help AI agents retrieve current web information instead of relying on guessed URLs or static model knowledge. The service injects structured, live search results into model context, supporting use cases involving recent events, evolving documentation, and changing APIs. Cloudflare says participating providers must meet its crawler standards by identifying verified bots, respecting robots.txt and site-owner preferences, and linking search results to their original sources. Developers can access the service through AI Gateway with unified billing, logging, access controls, optional zero-data-retention provider identification, list pricing without markup, and bring-your-own-key support, as well as through a REST API and Cloudflare Workers bindings. Cloudflare also plans to add native server tools to AI Gateway, with web search among the first built-in capabilities for agent workflows.
Oct 02, 2026
1,240 words in the original blog post.
Cloudflare has added optional email-based access controls to Quick Tunnels in cloudflared version 2026.9.3, allowing developers and coding agents to expose local services through temporary trycloudflare.com URLs while restricting access to specified email addresses or domains using the --allowed-mail flag. Visitors authenticate with a one-time PIN through Cloudflare Access, but authorization rules remain locally in cloudflared rather than being stored in a Cloudflare account, preserving Quick Tunnels’ account-free setup and keeping invite lists on the developer’s machine. Public tunnels remain unchanged when the flag is omitted, while protected tunnels end when the cloudflared process stops and require restarting to alter access rules. The feature also supports JSON output for agent workflows and is available through Wrangler for Workers users. Its architecture combines Cloudflare Access for identity verification with a stateless Workers-based broker that issues short-lived signed assertions, while cloudflared validates those assertions, enforces local rules, creates temporary sessions, and prevents authentication credentials from reaching the local application.
Oct 02, 2026
1,679 words in the original blog post.
Cloudflare reports progress toward making its platform’s capabilities available across Free, pay-as-you-go, and Enterprise plans, with plan differences increasingly based on usage limits rather than feature access. Newly expanded offerings include Logpush, Logpush Transformers, Custom Dashboards, broader role-based access control, Terraform support, resource tagging, network-management tools, identity and SCIM features, and MCP Server Portals. Customers can now create multiple accounts to separate teams, projects, and billing, while Enterprise customers can use Organizations, currently in beta and scheduled for general availability in October, to centrally manage accounts, analytics, auditing, and shared security configurations; free-account support is planned for early 2027. Cloudflare describes using this multi-account model internally, combining team autonomy with organization-wide security oversight and Terraform-based configuration management. The company also introduced billing visibility and budget alerts for non-Enterprise users, is testing hard spending caps for late 2026, and has substantially raised limits across products including Workers, Containers, Workflows, Browser Run, Vectorize, Pages, Durable Objects, and security tools. It says new Enterprise-only features will generally no longer be introduced, aside from specialized exceptions such as government-focused offerings.
Oct 02, 2026
2,393 words in the original blog post.
Cloudflare is launching a closed beta of its OHTTP Gateway, a managed service designed to help developers receive HTTP requests without learning users’ IP addresses or other identifying network metadata. Based on the IETF’s Oblivious HTTP standard, OHTTP separates traffic through independently operated relays and gateways: relays see client identifiers but not encrypted request content, while gateways decrypt requests for application servers without seeing the client’s identity, creating a double-blind privacy model. The new gateway complements Cloudflare’s renamed OHTTP Relay, formerly Privacy Gateway, and gives developers whose applications run behind Cloudflare or receive traffic from third-party relays an option that preserves this separation of trust. Deployed across Cloudflare’s global edge network, the service aims to reduce latency and operational complexity by automatically scaling, managing HPKE encryption keys, supporting standard and chunked OHTTP, allowing ordinary HTTP traffic alongside OHTTP, and integrating Cloudflare Access policies to authenticate relays. To prevent Cloudflare from operating both sides of an OHTTP exchange, the gateway will reject requests originating from Cloudflare Workers or proxied Cloudflare hosts, while developers remain responsible for avoiding personally identifying information within request bodies.
Oct 02, 2026
2,231 words in the original blog post.
Cloudflare has introduced eight observability updates intended to unify logs, traces, analytics, alerts, dashboards, and data exports across its platform. The release includes a consolidated Logs interface supporting datasets such as HTTP, security, Workers, Containers, R2, and AI Gateway; open-beta request tracing that follows traffic through Cloudflare to origins with OpenTelemetry export and W3C trace-context support; and a beta unified SQL API accessible to users, agents, the Cloudflare CLI, MCP server, and Workers bindings. Cloudflare is also adopting a unified ingestion- and storage-based pricing model for logs and traces beginning December 1, 2026, with free and paid usage tiers. Additional features include SQL-based custom alerts, 30 days of domain analytics retention on every plan, customizable cross-product dashboards, and Logpush availability for all self-service plans alongside SQL-based Transformers for processing exported data. Future plans include up to one year of telemetry retention, expanded OpenTelemetry support in Workers, and metrics export to OpenTelemetry-compatible destinations.
Oct 02, 2026
1,653 words in the original blog post.
Cloudflare reports that it was the fastest provider by TCP connection time in 74% of the world’s 1,000 largest networks in August 2026, rising from 60% in April and gaining leadership in 150 additional networks and 38 more countries. Its rankings use APNIC-estimated network populations and a trimean calculation of real-user TCP handshake times, measured through browser requests to Cloudflare and competitors including Amazon CloudFront, Google, Fastly, and Akamai. Alongside its longstanding error-page measurements, Cloudflare has introduced limited background testing on free Challenge Pages delivered through Turnstile, aiming to expand data coverage across more users, networks, and geographies without noticeable latency or added user interaction. The company says the larger dataset improves statistical confidence and ranking stability where providers differ by only milliseconds, while supporting future analyses weighted by users or grouped across countries and global traffic.
Oct 02, 2026
1,488 words in the original blog post.
Cloudflare has introduced Streamline, an open-source developer playground and reference architecture for building customizable video-processing pipelines on its Developer Platform. Streamline combines Workers for control and monitoring, Containers for long-running real-time media processing, and Durable Objects for session orchestration and preview relays, allowing applications to modify livestreams or hosted videos with features such as filters, image overlays, animated annotations, burned-in subtitles, re-encoding, and picture-in-picture. It accepts RTMP, HLS, and application-supplied webcam inputs, can send processed output to Cloudflare Stream via RTMP, and supports low-latency preview delivery over WebSockets. Its session-based API lets applications start, resume, monitor, supply media to, and stop pipelines while containers continue operating independently of client connections and are automatically limited by lifecycle controls. The current media engine uses FFmpeg internally, while its modular design could support other encoding technologies later. Security measures include Cloudflare Access authentication, isolated single sessions, protected Stream credentials, and per-session preview authorization. Cloudflare has released the media engine and demo application on GitHub, provided a public playground, and identified future possibilities including computer vision, hardware acceleration, WebRTC and MoQ support, and native media primitives in Workers.
Oct 02, 2026
3,083 words in the original blog post.
Cloudflare has introduced a new Early Access fraud dashboard for Account Abuse Protection that shifts fraud detection from one-time identity verification toward continuous, stateful assessment of account behavior, reflecting the growing ability of AI-enabled attackers to imitate legitimate identities and evade point-in-time checks. The platform creates privacy-preserving, per-domain Hashed User IDs from customer-provided login or signup identifiers, then builds account histories using observed login and signup events alongside device, network, location, and credential-risk signals. Fraud teams can use the dashboard to examine activity across an entire account population, identify suspicious concentrations by IP address, ASN, country, device, or failure rate, and drill into individual accounts to investigate events, leaked credential matches, and behavioral changes during attacks such as credential stuffing. Analysts can filter for high-risk accounts, consult event details and Cloudflare Ray IDs, and, when warranted, use Hashed User IDs in WAF rules to challenge or block future requests. The release also introduces separate access roles for dashboard use and personally identifiable information, supporting least-privilege controls, while complementing Bot Management by helping organizations investigate both automated and human-driven abuse in account creation and login flows.
Oct 02, 2026
1,448 words in the original blog post.
Cloudflare has introduced Cloudflare Traces in open beta, expanding automatic request tracing from Workers to supported operations across the full Cloudflare request path, including security rules, transformations, routing, caching, Worker execution, and origin handling. The service creates OpenTelemetry-compatible spans automatically without additional instrumentation, allowing users to inspect request timelines in the Cloudflare dashboard, control collection through baseline sampling and targeted Trace Rules, and trace selected traffic by properties such as headers, paths, IP addresses, or geography. It supports W3C traceparent context propagation so Cloudflare activity can connect with distributed traces from origins, external services, and applications, while OTLP export enables spans to be sent to compatible observability platforms. Cloudflare also highlights integration with its Observability MCP server for AI-assisted production debugging. Pricing will shift to a unified observability model on December 1, 2026, based on data ingestion and retention rather than span counts, and planned additions include broader instrumentation, authenticated propagation, on-demand tracing, expanded Workers OpenTelemetry APIs, and retention of up to 365 days.
Oct 02, 2026
1,423 words in the original blog post.
Cloudflare Impact is expanding support for civil society organizations by offering developer tools, security services, engineering assistance, and more than $7.5 million in credits to help nonprofits build secure, affordable AI applications. Building on Project Galileo’s protection of over 3,400 domains in more than 120 countries, the program addresses nonprofits’ growing need to create tools while managing financial constraints, sensitive data, privacy risks, and cyberattacks. Its first cohort of 30 organizations includes LebTown, which is automating newsroom workflows and public-records processing; Kaya Guides, which provides WhatsApp-based mental health counseling in India and uses AI feedback tools for counselors; and the Snorkelling Society, which is developing a community-powered snorkeling map. Cloudflare has also collaborated with Freedom House, the Global Network Initiative, and Article One on human-rights-focused systems that organize and assess large volumes of sensitive information while retaining human review for decisions and analysis. Following the initial cohort, Cloudflare has opened applications for a second group of nonprofit organizations.
Oct 02, 2026
1,620 words in the original blog post.
Cloudflare is inviting developers to build a new Git platform designed for an era in which large numbers of AI agents concurrently write, test, review, and maintain code. Its Artifacts product, now in open beta, provides programmable, Git-compatible versioned storage that can create and fork repositories at scale, preserve agent context, and support automated coordination workflows through Workers. Recent additions let users deploy repository code to Workers and preview environments, manage repositories through Workers bindings, trigger automation from repository events, select U.S. or EU data jurisdiction, and monitor repository operations and errors. The competition seeks projects that rethink collaboration concepts such as repositories, branches, reviews, conflict resolution, and agent context rather than simply adding agents to existing GitHub-style workflows; entries require a demonstration video, permissively licensed source code, and setup instructions by October 14, 2026. Winners will present at Cloudflare Connect in San Francisco, with the first-place team receiving $25,000 in Cloudflare credits, while Artifacts billing is scheduled to begin October 15, 2026.
Oct 01, 2026
1,308 words in the original blog post.
Cloudflare Workers has introduced opt-in Web Crypto support for post-quantum algorithms, including ML-KEM for key encapsulation and ML-DSA for digital signatures, enabling developers to experiment with quantum-resistant cryptography without bundling separate JavaScript or WebAssembly implementations. Available behind the `webcrypto_modern_algorithms` compatibility flag while the relevant specification remains in draft, the implementation includes APIs for encapsulating and decapsulating shared secrets, deriving public keys from private keys, checking runtime support, and importing or exporting keys as JWKs. ML-KEM can support protocols such as HPKE and OHTTP by providing shared key material for encryption schemes, while ML-DSA can be used for operations such as signing JWTs through libraries that delegate cryptography to the Workers runtime. Built into the open-source workerd runtime using BoringSSL primitives, the initial release supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87, though not ML-KEM-512, and it does not yet include other proposed modern Web Crypto features such as SHA-3, ChaCha20-Poly1305, cSHAKE, TurboSHAKE, or native HPKE. Cloudflare emphasizes that these APIs are foundational tools rather than a complete migration solution, and notes that larger post-quantum keys, signatures, and ciphertexts remain an operational consideration.
Oct 01, 2026
1,726 words in the original blog post.
Cloudflare has opened a waitlist for fully managed deployments of Cloudflare OS, an open-source agent workspace designed to connect organizational knowledge, data, and systems so teams can automate tasks, create tools, and produce materials such as documents and presentations. While organizations can already self-deploy the platform for full customization and control, the managed option lets Cloudflare handle deployment, operations, and updates while customers set access policies, available context, and connected systems through the Cloudflare dashboard. Recent additions allow agents to connect to GitHub repositories to inspect code, make edits, create commits, and open pull requests; work across Google Workspace by researching Gmail, drafting or sending email, and accessing Drive files; and export documents, presentations, and spreadsheets in formats including Excel, CSV, PDF, Markdown, and HTML.
Oct 01, 2026
738 words in the original blog post.
Cloudflare has introduced Workers KV Instant, a private-beta mode for Workers KV powered by its internal Quicksilver v2 system, designed for small, infrequently updated configuration data that must be globally available with very low latency. Using the same Workers KV API, Instant mode delivers p99 reads of roughly 1.62 milliseconds and replicates most writes worldwide in about 250 milliseconds, compared with slower cached and uncached reads and multi-second replication in classic Workers KV. It is intended for hot-path uses such as feature flags, routing settings, and launch controls, but differs from classic KV by requiring explicit namespace creation in Instant mode, excluding metadata support, returning all matching keys without pagination, limiting namespaces to 1 MB and 10,000 key-value pairs, and allowing one write per namespace per second. Reads cost $0.20 per million operations, 60% less than classic KV, while writes, lists, and storage are substantially more expensive at $0.10 per operation and $100 per MB monthly, reflecting its focus on read-heavy, compact datasets rather than frequently updated or large-scale storage.
Oct 01, 2026
1,197 words in the original blog post.
Cloudflare has made its serverless analytics platform generally available under the new name Cloudflare Basin, replacing the earlier Cloudflare Data Platform branding and consolidating Cloudflare Pipelines, R2 Data Catalog, and R2 SQL as Basin Pipelines, Basin Catalog, and Basin SQL. Built on Apache Iceberg and R2 Object Storage, Basin supports ingesting data from Workers, HTTP endpoints, Logpush, and other sources, transforming it with SQL, storing it as Iceberg tables or files, maintaining table metadata, and querying data through a distributed serverless SQL engine. The platform emphasizes rapid setup, scalable performance through compaction, metadata optimization, and distributed query execution, as well as data portability through compatibility with Iceberg tools such as DuckDB, PyIceberg, Snowflake, and Spark. Cloudflare highlights zero egress fees and usage-based pricing as cost advantages, while new and planned capabilities include higher pipeline throughput, data-quality visibility, Terraform support, joins and window functions in SQL, schema migrations, Iceberg V3 support, enhanced access controls, data sovereignty options, adaptive maintenance, and additional real-time processing features. Existing configurations using the previous product names will continue to operate, and developers can use Basin components together or independently within existing architectures.
Oct 01, 2026
2,255 words in the original blog post.
Cloudflare has launched K2 in public beta, a serverless durable event-streaming service designed to decouple data producers from consumers, retain events during downstream outages, and support both parallel work distribution and pub/sub fan-out patterns. Built initially as an edge buffering layer for Basin Pipelines, K2 stores ordered, partitioned logs on Cloudflare R2 object storage, using R2’s durability and consistency to simplify coordination while allowing compute and storage to scale independently. Events are accumulated into segments before being written to R2, resulting in approximately one second of 99th-percentile produce latency in the initial release. K2 differs from Cloudflare Queues by focusing on high-volume batch processing, long-term retention, and multiple consumers rather than per-message retries and work-item controls, while Pipelines is recommended for direct transformation and storage into R2 or Iceberg tables. Users can create streams through Cloudflare tools and APIs, produce byte-based events through HTTP or Workers bindings, and consume leased batches through subscriptions that can be acknowledged, rejected, or extended. During the beta, K2 is available to Workers Paid subscribers without charge under limits including 10 GB of storage and 30 MB/s production per stream, with planned future capabilities such as greater write throughput, key-based ordering, push consumers, lower-latency tiers, and Kafka client compatibility.
Oct 01, 2026
1,673 words in the original blog post.
Cloudflare announced that EuroLLM, a multilingual European model supporting 35 languages including all 24 official EU languages, and Apertus, Switzerland’s fully open multilingual model trained across more than 1,500 languages, are becoming available through Workers AI by request. Developed by public research institutions, the models are presented as options that can reduce reliance on individual AI providers while improving support for underserved and regional languages. The announcement builds on Cloudflare’s broader argument that AI sovereignty and resilience depend on choice, open standards, and the ability to switch between models, citing projects in India, Singapore, and Japan that used locally relevant language models for public services and healthcare communication. Cloudflare also introduced hands-on workshops for government cybersecurity agencies and critical infrastructure operators, beginning in Singapore in October, to help participants deploy an open-source AI security harness that coordinates multiple models to identify, verify, and prioritize vulnerabilities without depending on a single provider.
Oct 01, 2026
1,325 words in the original blog post.
Cloudflare has made AI Search generally available, offering a managed search and retrieval pipeline built on Workers AI, Vectorize, R2, and Browser Run for uses such as documentation and website search. The release expands multimodal capabilities with native image embeddings through Qwen3-VL-Embedding, combining direct visual matching with caption-based text understanding to improve retrieval for images, screenshots, products, charts, diagrams, and scanned content. AI Search also now supports text files and PDFs up to 10 MiB and can apply OCR to scanned PDFs before chunking and embedding. Queries can be rewritten, embedded, processed through vector and keyword search in parallel, fused, reranked, and either returned as chunks or passed to a generation model. Billing will begin on November 1, 2026, covering ingestion, storage, and semantic or full-text queries, while including parsing, chunking, embedding with eligible Workers AI models, indexing, and reranking; all Workers plans retain monthly free allowances. Cloudflare plans to add video and audio ingestion, improve keyword-search scalability, and simplify index creation for Cloudflare-hosted websites.
Oct 01, 2026
1,209 words in the original blog post.
Cloudflare has released Clef and Clef-flash, two open-source decision models hosted on Workers AI that produce bounded, typed classifications and calibrated probabilities for automated workflow decisions such as support routing, domain categorization, and security triage. Positioned as alternatives to open-ended, non-deterministic large language models, the models are Jev API-compatible, support structured outputs, and are designed for fast, programmatic use in agentic systems; Clef also supports image inputs and has a 64,000-token context window. Cloudflare reports that Clef led the Jev Decision Index and that both variants outperformed several competing decision models on many accuracy and latency evaluations, with Clef-flash targeting especially latency-sensitive applications. Built on Qwen backbones, the models score predefined schema choices directly rather than generating responses token by token, using specialized attention routing, probability-calibration training, and reinforcement-learning-based optimization. The company is making the models available under an Apache 2.0 license through Hugging Face and Workers AI, while also launching a fine-tuning service that initially involves Cloudflare engineers and is intended to evolve into a self-service reinforcement-learning platform using AI Gateway, Containers, Trainer, and bring-your-own-model deployment tools.
Oct 01, 2026
2,276 words in the original blog post.