Cloudflare uses AI harness to probe and harden its WAF
Cloudflare placed frontier AI models inside a controlled Python harness to generate and mutate attack payloads against its Web Application Firewall (WAF). Across 45 scenarios the system produced 1,107 mutation attempts, leaving 49 post-triage findings; the experiment contributed to three changes in Cloudflare’s Managed Ruleset (two new SSRF detections and an improvement to an existing SSRF rule), with human reviewers validating results before rule changes.