AI vulnerability triage becomes operational when code findings are ranked against live traffic, security signals, and the controls already in place
Source: Cloudflare
Cloudflare has announced invitation-only Early Access for Vulnerability Discovery and Remediation in Cloudflare Managed Defense. For codebases a customer authorizes it to inspect, the service uses OpenAI Daybreak models for reconnaissance, hunting, and validation, then combines source-code evidence with route activity, traffic, security events, and WAF context. It proposes code patches and mitigations for review; customers decide whether to implement them, and any WAF rule deployment requires authorization.
Why this matters: Do not let a model's confidence set remediation priority. Require corroborating code evidence, record the production-exposure signals used to rank a finding, keep every proposed patch and temporary mitigation reviewable, and define who can authorize, roll back, and audit a change. That turns AI assistance into a faster security decision loop without turning it into an unowned production actor.
Read Cloudflare's Vulnerability Discovery and Remediation announcement