Cloudflare Launches Vulnerability Defense Service with OpenAI
Cloudflare has integrated OpenAI's cybersecurity model into its security monitoring service, enabling it to identify code vulnerabilities in customer applications and prevent attacks at the edge. The aim is to expedite vulnerability detection using artificial intelligence (AI), prioritizing high-risk items in real operational environments.
On the 3rd, Cloudflare announced that it would offer its "Vulnerability Discovery and Response" service as an early access feature within its Managed Defense program in San Francisco, USA. The service is available to select enterprise customers invited by Cloudflare.
According to a statement from Cloudflare on the 3rd, as of September this year, the number of vulnerabilities registered in the U.S. National Vulnerability Database (NVD) has reached 60,475, surpassing the total of 48,185 registered in 2025. The company explained that even if existing vulnerability scanners present thousands of findings, a lack of operational context leads security teams to spend time identifying actual risks.
The new service utilizes the Daybreak Defense Network from OpenAI, incorporating the GPT-5.6 Cyber model. It conducts reconnaissance, exploration, and validation tasks on the codebase authorized by customers, linking these activities to actual traffic, security events, and edge control functions.
Unlike traditional scanners that merely increase the list of vulnerabilities, Cloudflare first creates a snapshot of traffic and security data from the web asset inventory and web application firewall (WAF). It then verifies which paths are actually open and whether there have been security events on those paths before narrowing down the scope of code investigation.
The reconnaissance agent connects the request paths with segments of the codebase. Subsequently, the exploration agent identifies vulnerabilities within the authorized code segments and assigns a risk rating after a validation process. If there is significant traffic through the path in the operational environment or confirmed exploration attempts, the priority is raised.
In the Workers environment, it retrieves the latest source version and configured routes to align with the actual endpoints. It also utilizes request metadata from Workers Observability to check whether code weaknesses are aligned with the actual service paths.
Cloudflare clarified that model inference does not occur at the edge. When customers approve the investigation, the workflow is executed within Cloudflare, and the model prompt is sent to the OpenAI server via the AI gateway in Workers. The response then returns to the Cloudflare workflow.
The key control mechanism is human approval. Cloudflare stated that code patches or firewall rules suggested by the model are not applied automatically, and all patch and rule suggestions must undergo customer review. The scope of investigation is also limited to the code and evidence authorized by the customer.
Matthew Prince, co-founder and CEO of Cloudflare, remarked, "If security teams are manually countering AI-based attacks, they are losing." This implies a shift from patching vulnerabilities one by one to an automated defense system.
McCall McIntyre, head of global cybersecurity partnerships at OpenAI, stated, "The goal of the OpenAI Daybreak Defense Network is to safely provide defenders with the advantages of frontier AI." This indicates a commitment to using high-performance models only in approved environments for defensive purposes.
OpenAI announced in a Daybreak expansion document released on August 10 that GPT-5.6 Cyber is provided at the Daybreak Red access layer. This model is based on GPT-5.6 and has been trained to enhance performance in specific cybersecurity tasks such as zero-day vulnerability discovery and exploit chain development.
In the same document, OpenAI reported that GPT-5.6 Cyber achieved a 95.0% completion rate in internal advanced cybersecurity assessments. The completion rate for GPT-5.6 was 1.5%, for the Daybreak Blue access GPT-5.6 it was 2.0%, and for GPT-5.5 Cyber it was 57.3%. This figure aligns with an approach aimed at reducing unnecessary rejections in high-risk tasks for defensive purposes.
However, OpenAI noted that GPT-5.6 Cyber falls under the "high" rating for cybersecurity capabilities within its readiness framework and has not reached the "critical" threshold. Previously, it was reported that OpenAI expanded Daybreak from vulnerability detection to a patching, validation, and deployment system.
There are also connections to the domestic crypto industry. Exchanges, wallets, payment services, and open-source libraries are areas where code vulnerabilities can lead to asset damage. Cloudflare's service focuses on prioritizing actual operational traffic and security events rather than just vulnerability detection itself.
Access to AI security tools remains a contentious issue. It was previously reported that Bitcoin security researchers raised concerns about restrictions on model access for defensive purposes. Strong models can quickly identify vulnerabilities and validate patches, but the same capabilities could be used for attack automation, prompting Cloudflare to place patch and firewall rule applications under human approval.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Web3 August Security Report: 29 Major Security Incidents Resulting in Over $68.29 Million in Losses

The fight over Ethereum’s supply is forcing a choice between high staking yields and the value of your ETH

Cardano’s Leios 6x scaling breakthrough comes with a much harder ADA problem

What Should CARF Report? Interpretation of Reporting Information and Local Implementation Differences

Three Major Lending Protocols Enter Fixed Rate Market: What Innovations Do They Bring?

Banca d’Italia demands checks on every crypto transfer

MoonPay CEO Asks Claude to Book a Flight Before Stuffing a Crypto Wallet into the Chatbox

Poland's crypto licensing deadlock benefits EU firms

HashKey Cloud joins Stacks Bitcoin staking launch

OpenAI Expenses in Campaigns: 39 US Candidates Paid for ChatGPT

Reviews of awx pro: what the crypto exchange offers, how trading works, and where the risks arise

Does the massive return of leverage threaten the recent rally?

Australia tightens crypto oversight with 45 removals

Strong jobs just triggered a hawkish UBS reversal that could pressure Bitcoin through December

Solana beats Bitcoin on one key metric, but a single software bug could still take down the network

Research Indicates Critical Threshold for Stablecoin Decoupling

Ethereum's Vitalik Buterin puts 60% odds on a cryptography breakthrough that could weaken Wall Street middlemen

Polymarket Report for the First Half of 2026: High-Frequency Traders or Super Forecasters?

Meta Creates AI Filter to Select Experiments Before Spending GPU Hours

TRON Industry Weekly Report: Non-Farm Payrolls Lean Hawkish but CPI Will Determine If BTC Can Hold Above 80,000, Detailed Analysis of KOR Protocol for Digital Content and IP Assetization

Wealthy Tax Avoidance: DeFi Lending Pools Take the Blame

唐华斑竹: USDD's Eighth Strategy Event Launched with a Total Prize Pool of $700,000

Raydium LaunchLab adds support for any token pair on Solana

Bercy Plans to Subject Employee Savings to Social Contributions in 2027

Altcoin open interest overtakes Bitcoin after 21 months

Atomic Time Faces Historic Change to Avoid Negative Leap Second

How Bitmine could surpass its 5% Ethereum goal without buying more ETH

OpenAI's GPT-6 Astra Is Shockingly Good at Almost Everything

Poland: Parliament Fails to Overturn Veto on Crypto Law










