AI Weekly Malaysia

Back to items Summaries

Enforce positive security with Cloudflare Application Profiles

ID
29819
Status
summarized
Published
29 Sep 2026, 9:00 PM
Fetched
29 Sep 2026, 10:55 PM
Provider
Cloudflare Blog
Category
infrastructure
Original URL
https://blog.cloudflare.com/application-profiles/
Source URL
https://blog.cloudflare.com/rss/

Summary

Score
5.0
Created
29 Sep 2026, 10:56 PM
Tags
Audience
developersai_ml_learnerssaas_founders

What happened

Cloudflare launched Application Profiles, a positive-security feature that periodically learns the expected structure and format of an app's HTTP requests, then runs an always-on validation layer that flags requests deviating from that learned profile. It extends the Schema Learning and Schema Validation it already offered for APIs to web applications, and is in closed beta for invited Enterprise customers without API Security (existing API Security customers already have access). Cloudflare frames the driver as LLM-enabled attackers who can generate malicious payloads and mutate tactics based on WAF feedback, arguing that 'patch faster' is not sustainable.

Why it matters

The concrete design idea is portable even if you never get the beta: allowlisting a field's format (Cloudflare's example is a search field that only accepts alphanumeric strings) kills a whole class of injection attacks without waiting on a patch. If you're on a non-Enterprise Cloudflare plan or another WAF, you can't switch this on, so the actionable move is per-field input schema validation in your own app — and if you're an Enterprise customer without API Security, request the invited beta. Treat the 'LLMs let anyone attack with one prompt' framing as vendor positioning, not a measured finding.

Discussion angle

Blocklists versus learned allowlists: if you already know the exact shape of a valid request to your search, login, or checkout endpoint, why are you still filtering for bad payloads instead of rejecting everything that doesn't match?

Top