Loading...

Cloudflare brings OpenAI AI models to vulnerability defence

Cloudflare has introduced a new Vulnerability Discovery and Remediation service that uses OpenAI’s Daybreak models, including GPT-5.6 Cyber, to help organisations identify, prioritise and address software vulnerabilities before they can be exploited.

The service, available in early access through Cloudflare Managed Defense, combines AI-powered code analysis and automated patch generation with real-time traffic and security intelligence from Cloudflare’s global network. The company said this approach can help security teams identify vulnerabilities that pose an immediate risk and block potential attacks at the network edge.

The launch comes as the number of newly identified software vulnerabilities continues to rise. Cloudflare said the National Vulnerability Database had recorded 60,475 vulnerabilities by September 2026, already exceeding the total reported during 2025.

Traditional vulnerability scanners can generate large volumes of findings, but often lack the real-world production context required to determine which vulnerabilities are actively being targeted. Cloudflare aims to address this challenge by combining code-level analysis with live Internet traffic and security signals.

The company’s global network processes trillions of requests each day across millions of web assets, giving it access to real-time signals that can help identify emerging attack patterns and potential zero-day threats.

“If your security team is manually fighting AI-driven attacks, you’re not just burning them out—you’re losing. Now, we’re shifting the defence strategy away from chasing patches one vulnerability at a time to an automated approach,” said Matthew Prince, Co-Founder and CEO, Cloudflare. “We built Cloudflare’s global network to analyse what’s happening across the Internet in real time. Pair that with the power of OpenAI GPT-5.6 Cyber, and you’re not just reacting to attacks anymore, you’re stopping them before they land.”

The service integrates AI-driven code analysis across Cloudflare’s platform, including Web Assets, WAF and Workers Observability. This allows eligible customers to connect vulnerability findings with activity occurring in live environments.

One of the key capabilities is identifying vulnerabilities that are currently facing active attack attempts. Cloudflare correlates live Internet traffic with vulnerability scans to help security teams focus on high-priority risks rather than spending resources on issues with limited immediate exposure.

The service can also provide temporary protection while developers work on permanent fixes. Customers can deploy custom Web Application Firewall (WAF) rules designed around specific attack vectors, allowing threats to be blocked at the edge before they reach vulnerable applications.

For longer-term remediation, OpenAI Daybreak models, including GPT-5.6 Cyber, can assist in generating code patches for developers to review and implement. Cloudflare said that no code change or edge security rule is deployed without explicit human approval.

“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, Head of Global Cyber Partnerships at OpenAI. “We are excited to team up with Cloudflare to put proactive, AI-driven security directly into the hands of enterprise defenders.”

Cloudflare Vulnerability Discovery and Remediation is currently available by invitation to selected Cloudflare Enterprise customers, with the service designed to help organisations move towards more proactive, context-driven vulnerability management.

Send news announcements/press releases to:
editor@thefoundermedia.com

About The Author