Cloudflare’s September 29, 2026 security announcements connect application behavior, traffic signals, and threat intelligence. Application Profiles identify requests outside an expected structure; Threat Signals turns selected reporting into account-scoped intelligence. Neither capability eliminates the need to decide when a signal should block legitimate traffic.
Positive security adds a different detection question
Application Profiles learns expected request structures and marks deviations. The announcement says the signal does not block by itself, and recommends observation before enforcement. Access includes customers with API Security and an invited closed beta for other Enterprise customers.
This approach can complement attack signatures by asking whether an input belongs to the expected application contract. It can also flag a newly valid request after a product release. Security and application teams should therefore own profile review together rather than assuming a deviation is always malicious.
Threat reporting needs context before enforcement
Threat Signals summarizes selected open-source reports, extracts indicators, and stores contextualized events in a private account dataset. The broader framework describes connecting code, runtime traffic, and intelligence.
An indicator can be relevant to one campaign without justifying a permanent global block. Preserve its source, confidence, age, and reason for use. Review whether a shared infrastructure address, domain, or tool appears in legitimate traffic before turning intelligence into a production rule.
Separate detection quality from response quality
A system can correctly detect an unusual input and still produce a bad response if it blocks a critical customer workflow. Begin with observation on a defined route set, compare signals with real outcomes, and identify false positives. Apply enforcement narrowly enough that its consequence can be understood.
Include ordinary releases, new clients, and low-volume operations in the evaluation. A learned profile may have less evidence for a rarely used administrative route than a popular search endpoint. Keep application validation and authorization in place; edge signals should add protection rather than replace the canonical checks.
Make rule changes reviewable
Record which evidence prompted a rule and who approved it. Monitor blocked requests and important business flows after rollout. Keep a controlled rollback path for incorrect enforcement, with enough context to avoid simply disabling all protections during an incident.
The useful promise is faster interpretation of security evidence. Its production value depends on reducing exposure without hiding legitimate failures. That requires bounded automation and shared ownership of the application contract.