
Cloudflare launches AI Crawl Control (formerly AI Audit) and introduces easily customizable 402 HTTP responses. Instead of blocking crawlers outright, content creators can now send "Payment Required" responses with custom messages, creating direct communication channels for AI partnerships.
WA
Will Allen, Pulkita Kini·August 28, 2025AI & ML 
AI Gateway simplifies AI app development with unified billing, secure key storage, and dynamic routing. Gain observability and control over costs, API keys, and traffic, connecting to major AI providers through a single endpoint.
MA
Michelle, Abhishek Kankani·August 27, 2025AI & ML 
In order to support a growing catalog of AI models while maximizing GPU utilization, Cloudflare built an internal platform called Omni. This platform uses lightweight isolation and memory over-commitment to run multiple AI models on a single GPU, allowing us to serve inference requests closer to users and improve overall availability across our network.
SM
Sven, Mari·August 27, 2025AI & ML 
Existing LLM serving engines aren’t efficient enough when deployed across a globally distributed network, so we built our own, in Rust. Infire is an LLM inference engine that employs a range of techniques to maximize resource utilization, allowing us to serve AI models more efficiently and with better performance for Cloudflare workloads.

We're expanding Workers AI with new partner models from Leonardo.Ai and Deepgram. Start using state-of-the-art image generation models from Leonardo (Phoenix, Lucid Origin) and real-time TTS and STT models from Deepgram (Nova 3, Aura 1). Build full-stack, low-latency AI applications, all hosted on Cloudflare's global network.

Cloudflare will provide confidence scores within our application library for Gen AI applications, allowing customers to assess their risk for employees using shadow IT.
AG
Ayush, Goldbe·August 26, 2025AI & ML 
GenAI tools bring power — and risk. Cloudflare CASB now scans ChatGPT, Claude, and Gemini for misconfigurations, sensitive data exposure, and compliance issues, helping organizations adopt AI with confidence.

This guide provides best practices for Security and IT leaders to securely adopt generative AI using Cloudflare’s SASE architecture as part of a strategy for AI Security Posture Management (AI-SPM).

We’re excited to announce Cloudflare MCP Server Portals are now available in Open Beta. MCP Server Portals are a new capability that enable you to centralize, secure, and observe every MCP connection in your organization. This feature is part of Cloudflare One, our secure access service edge (SASE) platform that helps connect and protect your workspace.

Cloudflare's AI security suite now includes unsafe content moderation, integrated into the Application Security Suite via Firewall for AI. Built with Llama, it detects and blocks harmful prompts before they reach your AI applications.
RM
Radwa, Mathias Deschamps·August 26, 2025Security 
The digital landscape of corporate environments has always been a battleground between efficiency and security. For years, this played out in the form of "Shadow IT" — employees using unsanctioned laptops or cloud services to get their jobs done faster. Security teams became masters at hunting these rogue systems, setting up firewalls and policies to bring order to the chaos. But the new frontier
NJ
Noelle, Joey Steinberger·August 25, 2025Security 
AI Avenue tackles fears, showcases AI's potential, and highlights positive human augmentation stories, even allowing hands-on interaction.
PS
Peter Saulitis, Craig Dennis·August 25, 2025AI & ML 
For years, developers have been stitching together multiple protocols for real-time media, trading latency for scale and simplicity. Media over QUIC (MoQ) is a new IETF standard that resolves this conflict, creating a single foundation for sub-second, interactive streaming at a global scale.

Fogos.pt, a volunteer-run wildfire tracker in Portugal, grew from a side project into a critical national resource used by citizens, media, and government. During 2025 fire season it was hit by DDoS attacks, but stayed online thanks to Cloudflare’s protections under Project Galileo.How a volunteer-run wildfire site in Portugal stayed online during DDoS attacks

AI face cropping for Images automatically crops around faces in an image. Here’s how we built this feature on Workers AI to scale for general availability.
DD
Deanna, Diretnan Domnan·August 20, 2025AI & ML 
Announcing the Browser Developer Program: Cloudflare’s new collaborative program to help shape Cloudflare challenges that work seamlessly with your browser. Get a direct communication channel, best practices guidelines, and early visibility into major updates. Join us today!
SO
Sallylee, Oliver Payne·August 18, 2025Frontend 
A new HTTP/2 denial-of-service (DoS) vulnerability called MadeYouReset was recently disclosed by security researchers. Cloudflare HTTP DDoS mitigation, already protects from MadeYouReset.
AF
Alex Forster, Noah·August 14, 2025Security 
You asked for simplicity. We listened. Introducing Externa and Interna, two new use-case-driven packages to simplify how you connect and protect your entire infrastructure.

Workers KV is Cloudflare's global key-value store, serving millions of requests per second across hundreds of billions of stored objects. The service powers critical infrastructure for dozens of Cloudflare products—from Access authentication to Pages static assets—making its availability essential to our platform's reliability. After the incident on June 12, we accelerated work to re-architect KV’
AR
Alex Robinson, Tyson Trautmann·August 8, 2025Security 
We significantly sped up our privacy proxy service by fixing a 40ms delay in "double-spend" checks. The issue stemmed from how Nagle's algorithm and delayed ACKs interacted with a third-party dependency.

OpenAI’s newest open-source models are now available on Cloudflare Workers AI on Day 0, with support for Responses API, Code Interpreter and Web Search (coming soon).
MA
Michelle, Ashish Datta·August 5, 2025AI & ML 
Perplexity is repeatedly modifying their user agent and changing IPs and ASNs to hide their crawling activity, in direct conflict with explicit no-crawl preferences expressed by websites.

An upcoming vulnerability disclosure in Cloudflare’s SSL for SaaSv1 is detailed, explaining the steps we’ve taken towards deprecation and how the newer Cloudflare for SaaS mitigates this risk through hostname verification.
MA
Mia, Albert Pedersen·August 1, 2025Security 
The White House AI Action Plan is a pivotal policy document outlining the current administration's priorities and deliverables in AI to establish American AI as the gold standard for AI worldwide.
ZZ
Zaid Zaid, Vincent Voci·July 25, 2025AI & ML 
Build and deploy real-time, decentralized Authenticated Transfer Protocol (ATProto) apps on Cloudflare Workers.

Faced with a data-ingestion challenge at a massive scale, Cloudflare's Business Intelligence team built a new framework called Jetflow. This post details the journey of its creation, from the architectural design to the specific code-level optimizations that resulted in a more than 100x efficiency improvement.

In Q2 2025, we observed Internet disruptions around the world resulting from government-directed shutdowns, power outages, cable damage, a cyberattack, and technical problems, as well as several with unexplained causes.

Microsoft disclosed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, that are exploited to attack SharePoint servers. Possession of these cryptographic machine keys allows an attacker to forge authentication tokens and maintain access even if the server is patched. Therefore, it is critical for customers to apply emergency patches to mitigate this threat.

This is part two of a story about how we overcame the challenges of making a complex system more scalable. It is about how we made Quicksilver, our highly distributed key-value store, scalable with regard to its data size by evolving to a tiered caching architecture.
MV
Marten Van De Sanden, Anton Dort Golts·July 17, 2025Distributed 
We’ve partnered with marimo to bring their best-in-class Python notebook experience to your Cloudflare data.
CR
Carlos Rodrigues, Jorge·July 16, 2025Languages 
Welcome to the 22nd edition of the Cloudflare DDoS Threat Report. Published quarterly, this report offers a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network. In this edition, we focus on the second quarter of 2025.

On July 14th, 2025, Cloudflare made a change to our service topologies that caused an outage for 1.1.1.1 on the edge, resulting in downtime for 62 minutes for customers using the 1.1.1.1 public DNS Resolver as well as intermittent degradation of service for Gateway DNS. We’re deeply sorry for this outage. This outage was the result of an internal configuration error and not the result of an attack
AP
Ash Pallarito, Joe Abley·July 15, 2025Security 
Gartner has recognized Cloudflare as a Visionary in the 2025 Gartner® Magic Quadrant™ for SASE Platforms report. We view this evaluation as a significant recognition of our strategy to help connect and secure workspace security and coffee shop networking, through our unique connectivity cloud approach.
AC
Abe, Corey Mahan·July 15, 2025Security 
This blog post is the first of a series, in which we share our journey in redesigning Quicksilver — Cloudflare’s distributed key-value store that serves over 3 billion keys per second globally. Here we discuss how we migrated from full datasets on each machine to a more scalable distributed design.
AD
Anton Dort Golts, Marten Van De Sanden·July 10, 2025Distributed 
Cloudflare chose TimescaleDB to power its Digital Experience Monitoring and Zero Trust Analytics products. TimescaleDB is a PostgreSQL extension designed for real-time analytics and time series data, and it helped us reduce query latency by 5–35x and cut storage footprint by 33x.

Cloudflare's SASE platform now offers egress policies by hostname, domain, content category, and application in open beta. This makes it easy to author simple and secure policies that control the source IP addresses that an organization's Internet traffic uses to connect to external services.

From May 2024 to May 2025, crawler traffic rose 18%, with GPTBot growing 305% and Googlebot 96%. This blog post explores crawling activity focused on AI and search web crawlers, and how 14% of top domains now use robots.txt rules to manage them.
JT
Joao Tome, Jorge·July 1, 2025AI & ML 
Cloudflare Radar now shows how often a given AI model sends traffic to a site relative to how often it crawls that site. This information can help site owners make decisions about which AI bots to allow or block, and enables users to understand how AI usage in aggregate impacts Internet traffic.
DB
David Belson, Sam·July 1, 2025AI & ML 
It’s Content Independence Day: Cloudflare, along with a majority of the world's leading publishers and AI companies, is changing the default to block AI crawlers unless they pay creators for content.
MP
Matthew Prince·July 1, 2025AI & ML 
Pay per crawl is a new feature to allow content creators to charge AI crawlers for access to their content.
WA
Will Allen, Simon Newton·July 1, 2025AI & ML 
Bots can start authenticating to Cloudflare using public key cryptography, preventing them from being spoofed and allowing origins to have confidence in their identity.
MA
Mari, Akshat Mahajan·July 1, 2025Security 
Cloudflare is making it easier for publishers and content creators of all sizes to prevent their content from being scraped for AI training by managing robots.txt on their behalf, and allowing targeted blocking of AI crawling on sites that serve ads.
JH
Jin Hee Lee, Dipunj Gupta·July 1, 2025AI & ML 
To celebrate United Nations Micro, Small, and Medium Sized Enterprises Day, Cloudflare is sharing success stories of small businesses building and growing on our platform and providing security guides to help protect their digital presence worldwide.
JS
Jocelyn, Smrithi Ramesh·June 27, 2025Security 
Since June 9, 2025, Internet users located in Russia and connecting to the open Internet have been throttled by Russian Internet Service Providers (ISPs).

Orange Meets, our open-source video calling web application, now supports end-to-end encryption using the MLS protocol with continuous group key agreement
MR
Michael Rosenberg, Kevin Kipp·June 26, 2025Security 
We’re building AI agents where logic and reasoning are handled by OpenAI’s Agents SDK, and execution happens across Cloudflare's global network via Cloudflare’s Agents SDK.

Cloudflare Containers are now available in public beta. Deploy simple, global, and programmable containers alongside your Workers.

We read NIST’s new guidance on “Implementing a Zero-Trust Architecture” so that you don’t have to. Read this to get the key points on the newly-released NIST Special Publication 1800-35.

In mid-May 2025, blocked the largest DDoS attack ever recorded: a staggering 7.3 terabits per second (Tbps).

We're open-sourcing use-mcp, a React library that connects to any MCP server in just 3 lines of code, as well as our AI Playground, a complete chat interface that can connect to remote MCP servers.

We are happy to announce the General Availability of Cloudflare Log Explorer, a powerful product designed to bring observability and forensics capabilities directly into your Cloudflare dashboard.

Today, June 12, 2025, Cloudflare suffered a significant service outage that affected a large set of our critical services, including Workers KV, WARP, Access, Gateway, Images, Stream, Workers AI, Turnstile and Challenges, AutoRAG, and parts of the Cloudflare Dashboard.
JH
Jeremy Hartman, Cj Desai·June 12, 2025AI & ML 
June 2025 marks the 11th anniversary of Project Galileo, Cloudflare’s effort to protect vulnerable public interest organizations from cyber threats. To celebrate, we’re sharing a new Radar report, expanding in Asia with two new partners, and highlighting stories from organizations on the front lines.

Cloudflare Workers now support FinalizationRegistry, but just because you can use it doesn’t mean you should. Dive into the tricky world of JavaScript and WebAssembly memory management and see why newer features make life a lot easier.
KG
Ketan Gupta, Harris Hancock·June 11, 2025Frontend 
How Knock shipped an AI Agent with human-in-the-loop capabilities with Cloudflare’s Agents SDK and Cloudflare Workers.

Forrester has recognized Cloudflare Email Security as a Strong Performer in the ‘current offering’ category in “The Forrester Wave™: Email, Messaging, And Collaboration Security Solutions.

Workers Builds, our CI/CD product for deploying Workers, monitors build issues by analyzing build failure metadata spread across over one million Durable Objects.

For the third consecutive year, Gartner has named Cloudflare to the Gartner® Magic Quadrant™ for Security Service Edge (SSE) report.

Cloudflare patched a vulnerability (CVE-2025-4366) in the Pingora OSS framework, which exposed users of the framework and Cloudflare CDN’s free tier to potential request smuggling attacks. After being notified, Cloudflare mitigated the issue within 22 hours.
EH
Edward H Wang, Andrew Hauck·May 22, 2025Security 
Real-time BGP route visualization is now available on Cloudflare Radar, providing immediate insights into global Internet routing. This new feature, accessible through the updated prefix pages or the API, enables operators to gain a better understanding of prefix routing status in real time.