IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Cloudflare launches AI vulnerability defence with OpenAI

Cloudflare launches AI vulnerability defence with OpenAI

Fri, 4th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Cloudflare has launched Vulnerability Discovery and Remediation with OpenAI Daybreak models. The service is available in early access through Cloudflare Managed Defence.

The product is designed to help customers identify software vulnerabilities, block attacks at the network edge, and generate code patch suggestions for engineering teams to review.

The launch comes as the volume of reported software flaws continues to rise. The National Vulnerability Database had logged 60,475 vulnerabilities by September, up from 48,185 in the whole of the previous year.

Security teams often face long lists of weaknesses from conventional scanners, but those tools do not always show which issues are being targeted in live environments. Cloudflare aims to address that by combining code analysis with traffic and security data from across its network.

The service uses OpenAI Daybreak models, including GPT-5.6 Cyber, alongside data from Cloudflare's web assets, web application firewall, and Workers observability tools. The goal is to help customers rank risks based on active threats rather than code findings alone.

Edge response

A central part of the offering is the ability to place temporary protections at the edge while software teams work on permanent fixes. Customers can instruct Cloudflare to deploy custom web application firewall rules tailored to a specific attack path.

The approach is intended to narrow the gap between the discovery of a flaw and the release of a software fix, a period security teams often regard as one of the most exposed in a vulnerability's lifecycle.

The service can also generate AI-based patch suggestions, with all proposed changes subject to human review before deployment. According to Cloudflare, no code fix or edge rule is applied without explicit approval.

Matthew Prince, Co-Founder and Chief Executive Officer of Cloudflare, linked the new service to the growing use of AI by attackers.

"If your security team is manually fighting AI-driven attacks, you're not just burning them out-you're losing. Now, we're shifting the defense strategy away from chasing patches one vulnerability at a time to an automated approach," said Matthew Prince, Co-Founder and Chief Executive Officer, Cloudflare.

He added: "We built Cloudflare's global network to analyse what's happening across the Internet in real time. Pair that with the power of OpenAI GPT-5.6 Cyber, and you're not just reacting to attacks anymore, you're stopping them before they land."

OpenAI tie-up

The launch extends a security partnership between Cloudflare and OpenAI through what the companies call the OpenAI Daybreak Defence Network. OpenAI said the goal is to apply frontier AI models to cyber defence in a controlled way.

"Our goal through the OpenAI Daybreak Defence Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI.

McIntyre added: "We are excited to team up with Cloudflare to put proactive, AI-driven security directly into the hands of enterprise defenders."

The service is available by invitation to selected enterprise customers. Cloudflare is positioning it as part of its managed defence offering rather than as a standalone mass-market release.

Rising pressure

The launch reflects broader pressure on corporate security teams as the number of disclosed vulnerabilities rises and attackers move more quickly to exploit them. Many organisations already use a mix of scanning tools, threat feeds, and patch management software, but a recurring challenge is deciding which flaws pose immediate operational risk.

By tying vulnerability discovery to live internet traffic patterns, Cloudflare is trying to distinguish itself from tools that focus mainly on code inspection or isolated telemetry. Its network processes trillions of requests each day across millions of web assets, giving threat intelligence teams a large data set for spotting emerging attack patterns.

For customers, the practical value will depend on how accurately the system distinguishes urgent risks from background noise, and whether AI-generated patch suggestions reduce developers' workloads without introducing new errors. Human approval remains part of the workflow, suggesting Cloudflare is presenting the product as decision support rather than full automation.

Eligible users can use the service to identify vulnerabilities under active attack, apply temporary edge protections, and review generated patches before implementation.