Cloudflare built a tester that lets a large language model (LLM – the type of AI behind ChatGPT) act like a hacker and try to bypass its web‑application firewall (WAF). The system ran 45 scenarios covering XSS, SQLi, CMDi, SSRF, LFI and Log4j against a staging environment and generated 1,107 request attempts. After human review, 49 attempts were deemed real findings, 48 of them for command injection or SSRF, and the work resulted in three new managed‑ruleset detections released on July 21.
Why it matters
The test shows AI can quickly expose WAF gaps, helping Cloudflare improve protection for all customers.