Independent tech intelligence, checked against primary sources.

TechPulseMind Useful technology.
No manufactured hype.

Cloudflare Ran 1,107 AI Attack Attempts Against Its Own WAF

Cloudflare used frontier AI models to attack its own WAF across six categories, logging 1,107 attempts. Most were blocked; bypasses became new detections.

Cloudflare Ran 1,107 AI Attack Attempts Against Its Own WAF

Cloudflare built an AI-powered tester that fired 1,107 attack attempts at its own Web Application Firewall, and says the vast majority were blocked. The company detailed the experiment in a blog post published September 29, 2026, describing how frontier AI models were used to mutate known exploits against an authorized customer staging environment.

The setup is a closed loop with no human in the middle. According to Cloudflare, the tester starts from an exploit the WAF already blocks, then an LLM proposes a variation — a different encoding, a different position in the HTTP request, or a move to another vulnerability — and sends it. A second model call reviews the response status, selected headers and body, and the loop continues until mutations stop producing useful variations or a hard-coded attempt limit is hit.

Crucially, Cloudflare says neither model call had access to WAF internals. “Neither receives rule expressions, rule IDs, WAF Attack Score,” the company writes. The LLM also had no visibility into source code, so it was working blind, the way an outside attacker would.

What got through, and what Cloudflare did with it

The tester ran across six attack categories. Cloudflare says it reviewed the requests that were not blocked and removed malformed, benign, duplicate and out-of-scope observations before drawing conclusions. A request that slipped past the WAF was treated as a lead for human review, not a confirmed exploit — an important distinction, since a payload still needs an exploitable application to do damage.

The bypasses that survived review were used to write new detections. Cloudflare says the exercise is becoming a foundational building block of its WAF development lifecycle, and that the hardening benefits all Cloudflare customers, not just the staging environment tested.

If you run a WAF in front of your own app, Cloudflare’s takeaway is blunt: patch your software. The company notes that keeping your stack up to date remains one of the strongest defenses, because a WAF bypass alone does not compromise an application. Cloudflare has previously framed its application security work around linking code, traffic and threat intelligence; this testing loop is another piece of that effort.

The full write-up, including the attack categories tested and which vectors bypassed the WAF more easily, is available on Cloudflare’s blog.

Related reading

Sources

Some links on this page may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.