AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-2 of 2 results

DateProviderScoreSummary
29 Sep 2026, 9:00 PMCloudflare Blog5.0 Enforce positive security with Cloudflare Application Profiles

Cloudflare launched Application Profiles, a positive-security feature that periodically learns the expected structure and format of an app's HTTP requests, then runs an always-on validation layer that flags requests deviating from that learned profile. It extends the Schema Learning and Schema Validation it already offered for APIs to web applications, and is in closed beta for invited Enterprise customers without API Security (existing API Security customers already have access). Cloudflare frames the driver as LLM-enabled attackers who can generate malicious payloads and mutate tactics based on WAF feedback, arguing that 'patch faster' is not sustainable.

Why: The concrete design idea is portable even if you never get the beta: allowlisting a field's format (Cloudflare's example is a search field that only accepts alphanumeric strings) kills a whole class of injection attacks without waiting on a patch. If you're on a non-Enterprise Cloudflare plan or another WAF, you can't switch this on, so the actionable move is per-field input schema validation in your own app — and if you're an Enterprise customer without API Security, request the invited beta. Treat the 'LLMs let anyone attack with one prompt' framing as vendor positioning, not a measured finding.

29 Sep 2026, 9:00 PMCloudflare Blog4.5 We tested our own WAF with frontier AI models. Here’s what we found

Cloudflare built an LLM-driven "WAF tester" that takes known exploits and iterates on them — changing encoding, moving the payload to a different part of the HTTP request, or switching vulnerability — using only selected HTTP response data as feedback, with no visibility into source code or WAF rules. Run against an authorized customer staging environment across six attack categories, it recorded 1,107 attempts; the vast majority were blocked, and non-blocked requests were treated as leads for human review rather than confirmed exploits, feeding new detections into the WAF. The post does not publish a bypass rate or a per-category breakdown of what got through, and Cloudflare is testing its own product.

Why: The concrete takeaway is Cloudflare's own framing: a payload that slips past a WAF still needs an exploitable application to succeed, so keeping your stack patched remains the stronger defense — don't let a WAF subscription stand in for dependency updates. The second takeaway is methodological: this is a vendor reporting on its own product with no bypass number published, so treat "the vast majority were blocked" as an unquantified claim when you evaluate any WAF vendor's AI-resistance messaging, Cloudflare included. There is no Malaysia-specific detail in the text.

Top