We tested our own WAF with frontier AI models. Here’s what we found

Cloudflare Version 1 original current

Imported from official source

We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an authorized staging environment and discovered detection gaps worth fixing. Here’s how the loop worked, what got through, and what we did about it.

This version

Version
1 of 1
Recorded
September 29, 2026 14:00
Change
Initial
Content hash
e4949fa3604b8e2f49fa95992e917634
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.