Cloudflare has introduced a new capability designed to automate the processing of unstructured threat intelligence reports. Threat Signals, launched today, uses agentic AI to transform open-source security research into structured, contextualized indicators that can be directly applied to web application firewall (WAF) policies. The tool is available at no cost to all Cloudflare account holders, including free tiers, and integrates with the company’s broader Threat Events Platform, which has also been opened to all users without charge.
How the system works
Threat Signals operates by monitoring RSS feeds selected by the user, supporting RSS 2.0, Atom, and RDF formats. When new content is detected, the system fetches and converts the article into a cleaned markdown format stored in Cloudflare’s R2 object storage. The text is then processed through a series of predefined "skills"—detailed instructions that replicate the steps a human analyst would take. These skills summarize the report, extract and normalize indicators of compromise (IOCs), apply tags based on the user’s existing taxonomy, and preserve the link to the original source. The output is stored as a Threat Event within the user’s private dataset, where it remains searchable and connected to its source material for up to 30 days.
The tool is designed to address a longstanding challenge in threat intelligence: the manual effort required to convert unstructured reports into actionable data. Analysts typically spend significant time reading, summarizing, and formatting reports before they can be used in security tools. Threat Signals automates these steps while maintaining the context that explains why specific indicators matter, reducing the risk of losing critical details during the process. For enterprise customers on Essentials, Advantage, or Elite plans, additional features are available, including support for more RSS feeds, access to proprietary threat datasets, custom skill creation, and extended storage options.
Why context matters
One of the key insights from the development process was the importance of preserving the connection between indicators and their original reports. Early testing revealed that analysts frequently returned to the source material during investigations to understand the reasoning behind specific IOCs. This link, often lost in traditional threat intelligence platforms, helps teams assess risk and make informed decisions during remediation. Cloudflare also found that analysts were more likely to trust automated tagging when they could see which tags were applied by the system versus those added manually, a distinction the tool now explicitly records.
Background: Threat intelligence platforms (TIPs) aggregate and analyze data about emerging cyber threats, such as malware, phishing campaigns, or vulnerabilities. These platforms help security teams prioritize and respond to risks by providing structured indicators of compromise (IOCs), such as IP addresses, domains, or file hashes. Open-source threat intelligence relies on publicly available reports from researchers, government agencies, and security vendors, which are often published in unstructured formats like blog posts or PDFs.
What’s next
Cloudflare has indicated that RSS feeds are only the starting point for Threat Signals. The company plans to expand the tool’s data ingestion capabilities to support additional formats and pipelines, allowing analysts to consume threat intelligence from a broader range of sources. The goal is to create a more flexible platform that can adapt to the varied ways security teams collect and process information. For now, users can set up Threat Signals through the Cloudflare dashboard under Application Security → Threat Intelligence → Threat Signals, where they can add and configure their preferred RSS feeds.
Companies mentioned
Automated pipeline · SaaS
Synthesized from 1 industry feed on 29 Sep 2026. Passed independent editor verification (score 92/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No prior coverage of Cloudflare's Threat Signals for open-source threat intelligence.
- Writing the article — Draft created article_id=624 slug=cloudflare-launches-free-ai-driven-threat-intelligence-tool
-
Editor review — Approved
- Score: 92/100
- Factual grounding: The draft states 'RDF formats' are supported, but the source specifies 'RSS 1.0/RDF' — while technically correct, the phrasing could be more precise to match the source's exact terminology.
- Style compliance: The Background block exceeds the recommended 2-4 sentences, providing more detail than necessary for context. It should be tightened to focus only on essential definitions.
- No copied phrasing: The phrase 'transform open-source security research into structured, contextualized indicators' closely mirrors the source's 'turns open-source reporting that you choose into intelligence you can act on' — restructuring is needed to avoid echoing the source.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #51
- Linking related stories — Linked 5 relations from 324 candidates
- Publishing — Published cloudflare-launches-free-ai-driven-threat-intelligence-tool
- Mastodon — Posted https://mstdn.social/@hostingpaper/117355130522850017




Discussion · coming soon
Be the first to join the thread when community discussion launches.