3 Sources
[1]
Cloudflare taps OpenAI's cyber models to find and block code flaws
Cloudflare taps OpenAI's cyber models to find and block code flaws Cloudflare Inc. today opened early access to Vulnerability Discovery and Remediation, a service that uses OpenAI Group PBC's cybersecurity models to find software flaws in customer applications and block attacks on them at the
[2]
Cloudflare Partners with OpenAI Daybreak Models to Redefine Vulnerability Management with AI-Powered Edge Defense
New Cloudflare Vulnerability Discovery and Remediation service uses OpenAI Daybreak models to find, block, and fix software vulnerabilities -- often before security teams even know there is a problem Cloudflare, Inc. today announced Vulnerability Discovery and Remediation, available in early
[3]
Cloudflare launches AI-powered vulnerability detection service By Investing.com
SAN FRANCISCO - Cloudflare Inc. (NYSE:NET) announced today the launch of Vulnerability Discovery and Remediation, a service that uses OpenAI models to identify and address software vulnerabilities, according to a company press release. The service, available in early access through Cloudflare
Share
Copy Link
Cloudflare launched Vulnerability Discovery and Remediation, an AI-powered service using OpenAI Daybreak models including GPT-5.6 Cyber. The service identifies software vulnerabilities in customer applications and blocks attacks at the network edge in real-time. With 60,475 vulnerabilities logged by September 2026 versus 48,185 in all of 2025, the service addresses the growing gap between vulnerability discovery and remediation through automated code analysis and custom firewall rules.
Cloudflare opened early access to Vulnerability Discovery and Remediation, a service that combines OpenAI Daybreak models including GPT-5.6 Cyber with real-time traffic analysis to identify and block software vulnerabilities before exploitation
1
2
. The service runs inside Cloudflare Managed Defense, the company's security operations center offering, and reaches the cybersecurity models through the Daybreak Defense Network1
. Matthew Prince, Cloudflare's co-founder and CEO, stated that teams fighting AI-driven attacks manually are losing, emphasizing the need to shift from chasing patches one vulnerability at a time to an automated approach2
.The National Vulnerability Database logged 60,475 vulnerabilities by September 2026, already surpassing the 48,185 total recorded across all of 2025
2
3
. Traditional vulnerability scanners surface thousands of findings without production context to show which ones deserve attention first, leaving teams sorting through noise while real threats slip through unaddressed2
. The window between vulnerability discovery and remediation has become one of the most dangerous gaps in enterprise security2
.Cloudflare takes a snapshot from its Web Assets inventory and web application firewall showing which routes are live and what security events they have generated
1
. A reconnaissance agent maps request paths to sections of the codebase, while hunter agents work from that map to identify vulnerabilities1
. Code running on Cloudflare Workers is pulled in through Workers Observability1
. Every finding is validated before receiving a risk rating, which increases if production evidence shows heavy traffic or active probing against the affected route1
.
Source: SiliconANGLE
The process generates two types of fixes. Custom WAF rules scoped to the method, path and request details needed to reach vulnerable code can be deployed as a stopgap while developers work
1
. OpenAI Daybreak models also draft automated patches for engineers to review1
2
. No rule and no patch takes effect without explicit human approval, and the models cannot apply either one independently1
.Prompts travel through Cloudflare AI Gateway to OpenAI servers, with no inference running on Cloudflare's own edge
1
. Redaction strips out context the model does not need, and every proposal must pass checks written outside the model1
. A failed check stops the workflow before a customer sees anything1
. This layered approach ensures proactive security while maintaining control over sensitive code and infrastructure.GPT-5.6 Cyber arrived in August when OpenAI split Daybreak into two access tiers, placing the model behind Daybreak Red for vulnerability research and exploit validation
1
. The model completed 95% of advanced cybersecurity requests on OpenAI's benchmark, compared to 1.5% for the general-purpose GPT-5.6 Sol1
. McCall McIntyre, Head of Global Cyber Partnerships at OpenAI, said the network aims to give defenders the advantage of frontier AI safely1
3
.Related Stories
Palo Alto Networks deployed the same models inside its Unit 42 consulting engagements last month
1
. Proofpoint announced that Daybreak models now power a SOC Analyst Agent for threat investigation1
. OpenAI committed $1 billion to subsidized Daybreak access for water and electricity utilities, local government, community banks and nonprofits1
. This expansion signals growing confidence in AI-driven defense capabilities across critical infrastructure.Access is by invitation only for select Cloudflare enterprise customers, with each engagement beginning with one application the customer nominates
1
. Pricing was not disclosed, and Cloudflare provided no timeline for moving beyond early access1
. Organizations should monitor how the service performs in production environments and whether the combination of real-time traffic analysis with code analysis delivers measurable reductions in exploit windows. The partnership between Cloudflare and OpenAI represents a shift toward context-aware prioritization where network edge protection meets deep code investigation, potentially reshaping how enterprise defenders respond to the accelerating pace of vulnerability disclosures.Summarized by
Navi
22 Jun 2026•Technology

07 Aug 2026•Technology

25 Aug 2025•Technology

1
Policy and Regulation

2
Technology

3
Technology
