Cloudflare Threat Signals is open to all accounts—with one free RSS feed

SNACK: 3-line summary

  • Cloudflare has launched Threat Signals for every Cloudflare account.
  • Website operators can search indicators drawn from security reports and follow them back to their sources.
  • Free access covers one RSS feed and up to 30 days of data; custom WAF rules are an enterprise feature.

Cloudflare announced Threat Signals on September 29, giving website and security teams a way to turn an open-source research feed into a private, searchable collection of threat events.

Official Threat Signals announcement visual
Official Threat Signals announcement visual. Image: Cloudflare.

Snackgirls react

AIKO: I’m curious how a feed item becomes a normalized indicator and a tagged event. That link between the original report and the searchable record is the useful bit.

Nea: If an indicator catches my eye, I’d want to read the report it came from before treating it as a warning. Keeping that trail intact matters.

Start with a research feed

Threat Signals collects reports from an RSS feed selected by the account holder. Cloudflare says it supports RSS 2.0, Atom and RSS 1.0/RDF feeds, so operators can bring in a source they already follow.

Threat Signals RSS feed dashboard
Threat Signals RSS feed dashboard. Image: Cloudflare.

From report to indicator—and back again

Cloudflare says the service summarizes each report, extracts and normalizes indicators of compromise, and stores them with tags as account-private Threat Events. Each event retains a link to its originating report. A flagged indicator is a starting point for investigation, not proof on its own that a domain is malicious.

Threat Signals article summary and indicators
Threat Signals article summary and indicators. Image: Cloudflare.

Where free access stops

Every Cloudflare account gets one RSS feed, dashboard and API access, and a private derived dataset retained for up to 30 days. Cloudflare says Enterprise Essentials, Advantage and Elite customers may get additional feeds, proprietary Cloudforce One datasets, custom agentic skills and higher retention or storage. The ability to create custom WAF rules from threat events is part of that enterprise offering, not the free access.

Where to find it

In the Cloudflare dashboard, go to Application Security → Threat Intelligence → Threat Signals to add a feed. Teams can then use Threat Signals and the Threat Events Platform to investigate the resulting indicators and tags.

Sources and checked date: Cloudflare · September 30, 2026

Related hashtags
#GameSunakku #Cloudflare #ThreatSignals #ThreatIntelligence #Cybersecurity #RSS

Game Sunakku에서 더 알아보기

지금 구독하여 계속 읽고 전체 아카이브에 액세스하세요.

계속 읽기