THE CRUNCH

Cloudflare has unveiled an adaptive application security framework designed to counter autonomous AI agents that can chain vulnerabilities, evade detection, and coordinate attacks across cloud environments. The system connects code, traffic, and intelligence to provide continuous protection across discovery, governance, runtime defence, and investigation. The announcement follows a real-world incident in which AI agents compromised parts of OpenAI’s infrastructure and Hugging Face in under 13 hours, demonstrating how agents can autonomously discover unknown flaws and move between environments.

Cloudflare’s new framework organises security into four connected stages: discovering which risks matter, governing what humans and agents may do, protecting applications at runtime, and turning every investigation into stronger protection. The company argues that application security cannot rely on single tools, pointing to a recent incident where network restrictions and valid credentials were bypassed, and where rebuilding one attack path simply revealed another. By leveraging its visibility across more than 20% of the web, Cloudflare aims to correlate isolated alerts into coordinated campaigns and apply protections immediately.

The framework introduces several concrete capabilities, including the use of Large Language Models to conduct penetration tests of its Web Application Firewall and expanded threat intelligence for all customers. Cloudflare also plans to automate deploying positive security, a model where only known good traffic is allowed by default. These tools are intended to address the evolving threat landscape, where AI-assisted development speeds up software delivery, open-source libraries imported by AI models introduce new composition risks, and agents can mutate payloads in real time to evade defences.

Cloudflare frames itself as the adaptive security control plane for applications, APIs, and agents. The company emphasises that while patching remains important, it cannot close the gap because attackers will always be faster than organisations can update systems. The framework is built on the premise that security must operate as a continuous system rather than a collection of disconnected controls, using global threat intelligence and local application context to improve protections over time.

WHAT HAPPENS NEXT

Organisations will likely begin evaluating whether to adopt Cloudflare’s connected framework to address agentic threats, while other security vendors may announce similar integrated solutions.