Cloudflare Launches Vulnerability Defense Service with OpenAI
Cloudflare has integrated OpenAI's cybersecurity model into its security monitoring service, enabling it to identify code vulnerabilities in customer applications and prevent attacks at the edge. The aim is to expedite vulnerability detection using artificial intelligence (AI), prioritizing high-risk items in real operational environments.
On the 3rd, Cloudflare announced that it would offer its "Vulnerability Discovery and Response" service as an early access feature within its Managed Defense program in San Francisco, USA. The service is available to select enterprise customers invited by Cloudflare.
According to a statement from Cloudflare on the 3rd, as of September this year, the number of vulnerabilities registered in the U.S. National Vulnerability Database (NVD) has reached 60,475, surpassing the total of 48,185 registered in 2025. The company explained that even if existing vulnerability scanners present thousands of findings, a lack of operational context leads security teams to spend time identifying actual risks.
The new service utilizes the Daybreak Defense Network from OpenAI, incorporating the GPT-5.6 Cyber model. It conducts reconnaissance, exploration, and validation tasks on the codebase authorized by customers, linking these activities to actual traffic, security events, and edge control functions.
Unlike traditional scanners that merely increase the list of vulnerabilities, Cloudflare first creates a snapshot of traffic and security data from the web asset inventory and web application firewall (WAF). It then verifies which paths are actually open and whether there have been security events on those paths before narrowing down the scope of code investigation.
The reconnaissance agent connects the request paths with segments of the codebase. Subsequently, the exploration agent identifies vulnerabilities within the authorized code segments and assigns a risk rating after a validation process. If there is significant traffic through the path in the operational environment or confirmed exploration attempts, the priority is raised.
In the Workers environment, it retrieves the latest source version and configured routes to align with the actual endpoints. It also utilizes request metadata from Workers Observability to check whether code weaknesses are aligned with the actual service paths.
Cloudflare clarified that model inference does not occur at the edge. When customers approve the investigation, the workflow is executed within Cloudflare, and the model prompt is sent to the OpenAI server via the AI gateway in Workers. The response then returns to the Cloudflare workflow.
The key control mechanism is human approval. Cloudflare stated that code patches or firewall rules suggested by the model are not applied automatically, and all patch and rule suggestions must undergo customer review. The scope of investigation is also limited to the code and evidence authorized by the customer.
Matthew Prince, co-founder and CEO of Cloudflare, remarked, "If security teams are manually countering AI-based attacks, they are losing." This implies a shift from patching vulnerabilities one by one to an automated defense system.
McCall McIntyre, head of global cybersecurity partnerships at OpenAI, stated, "The goal of the OpenAI Daybreak Defense Network is to safely provide defenders with the advantages of frontier AI." This indicates a commitment to using high-performance models only in approved environments for defensive purposes.
OpenAI announced in a Daybreak expansion document released on August 10 that GPT-5.6 Cyber is provided at the Daybreak Red access layer. This model is based on GPT-5.6 and has been trained to enhance performance in specific cybersecurity tasks such as zero-day vulnerability discovery and exploit chain development.
In the same document, OpenAI reported that GPT-5.6 Cyber achieved a 95.0% completion rate in internal advanced cybersecurity assessments. The completion rate for GPT-5.6 was 1.5%, for the Daybreak Blue access GPT-5.6 it was 2.0%, and for GPT-5.5 Cyber it was 57.3%. This figure aligns with an approach aimed at reducing unnecessary rejections in high-risk tasks for defensive purposes.
However, OpenAI noted that GPT-5.6 Cyber falls under the "high" rating for cybersecurity capabilities within its readiness framework and has not reached the "critical" threshold. Previously, it was reported that OpenAI expanded Daybreak from vulnerability detection to a patching, validation, and deployment system.
There are also connections to the domestic crypto industry. Exchanges, wallets, payment services, and open-source libraries are areas where code vulnerabilities can lead to asset damage. Cloudflare's service focuses on prioritizing actual operational traffic and security events rather than just vulnerability detection itself.
Access to AI security tools remains a contentious issue. It was previously reported that Bitcoin security researchers raised concerns about restrictions on model access for defensive purposes. Strong models can quickly identify vulnerabilities and validate patches, but the same capabilities could be used for attack automation, prompting Cloudflare to place patch and firewall rule applications under human approval.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

BulkTrade Launches USDC Margin Perpetual Contract Exchange on Solana Mainnet

Spark, Bitcoin's L2, Collides with the Open Source Culture of Its Own Ecosystem

OCEAN Reactivates Lightning After Damage from Dashjr's Bet on BIP-110

How the “buy, borrow, die” tax trade is quietly loading DeFi pools with hidden credit risk

Venture Capital Funding in Crypto: $292 Million, 93% in Stablecoins and Banks

Robinhood Chain Drives UNI Token Burn to $1.15 Million

August Sees 50 Cyber Attacks in Crypto Industry, Losses Reach $136.3 Million, AEREDIUM Launches AERSeal

Bitcoin Must Drop 83% to $13,136 to Reach STRC 1x BTC Rating

Why 89% of tokenized RWAs remain idle despite a $34.6 billion market: Falcon exec explains

30-Year Bond Yield Hits 4.079%, Raising Funding Costs for MetaPlanet's Bitcoin Purchases

Japan’s 4% bond yield spike threatens the low-cost borrowing strategy behind corporate Bitcoin buying

Arthur Hayes calls EUR/JPY prices crypto’s smoke alarm, but the Fed’s plumbing still shows no fire

Why GENIUS could leave digital dollars vulnerable to sudden blockchain network ‘bank runs’

Stocks, Bonds, Funds: Seoul Prepares for Their Arrival on the Blockchain

Capital B consolidates its shares at 10 to 1, a week after bringing Adam Back into the capital

The Share of Cashless Payments in Russia Decreased to 88.4%

From Bitcoin to oil, perpetual contracts are breaking into American financial markets

Bitcoin Knots Developer Claims Exchanges Sell Fake Bitcoins

Beyond APR: Who Really Owns Your ETH After Staking?

Bitcoin vs Gold: The Battle of Safe Havens Resumes

What Really Happened with Agents in Q2 Earnings Season of US and A-shares

OpenAI's Cybersecurity Program Worth $1 Billion

Why Traditional Investment Portfolios Have Failed?

Crypto and Terrorism: 4,267 USDT at the Heart of a Trial in South Korea

Sanders bill seeks permanent US ban on superintelligent AI

Senescent Microglia Release DLK1 and Deteriorate the Aging Brain

OpenAI Releases GPT-6 Astra: The Closest AI Model Yet to AGI

The Cost of AI Tokens in Free Fall: Should We Be Worried?

Bahrain Leads the Race for Stablecoins in the Middle East, But Where Are the Coins?







