Oossa

Cloudflare tests its WAF against advanced AI models

A custom AI‑driven tester sent 1,107 attack attempts to a customer staging site; most were blocked, leading to three new rule updates.

NoteOossa1 min read

Cloudflare built a tester that lets a large language model (LLM – the type of AI behind ChatGPT) act like a hacker and try to bypass its web‑application firewall (WAF). The system ran 45 scenarios covering XSS, SQLi, CMDi, SSRF, LFI and Log4j against a staging environment and generated 1,107 request attempts. After human review, 49 attempts were deemed real findings, 48 of them for command injection or SSRF, and the work resulted in three new managed‑ruleset detections released on July 21.

Why it matters

The test shows AI can quickly expose WAF gaps, helping Cloudflare improve protection for all customers.

Was this article useful?
Share

Read next

Oossa · Newsletter

The week in AI, explained

Every Monday: the stories worth knowing, in plain language. Free, no spam.

Sources & references

#SourceOutletDateKey takeaway
1We tested our own WAF with frontier AI models. Here’s what we found ↗CloudflareSep 29, 2026We built a WAF tester that adapted each request based on what the WAF blocked or passed.

1 sources

Last updated: ·Markdown·llms.txt