2026
18 篇文章當掃描器看不見攻擊:Cloudflare 用 ML 拆解店面前的惡意 JavaScript
Cloudflare 的 Page Shield ML 在真實流量中攔下八個惡意 payload,而 VirusTotal 與 URLScan 幾乎全部漏判。
閱讀文章 ↗當 agent 也能改 production:Cloudflare 把 Workers 權限切到單一資源
Cloudflare 為 Workers 推出四種角色與資源層級授權,讓 CI 與 agent 只拿到單一 Worker 的權限。
閱讀文章 ↗讓搜尋爬蟲進來、訓練爬蟲出去:Cloudflare 把混合用途爬蟲拆成三種行為
Cloudflare 推出 Disallow AI Training,讓站長在保留搜尋收錄的同時拒絕 AI 訓練,並把爬蟲控制拆成 Search、Training、Agent 三類。
閱讀文章 ↗Cloudflare 聯手 OpenAI Daybreak:用網路脈絡解決漏洞優先順序難題
Cloudflare 推出 Vulnerability Discovery and Remediation 早期存取服務,結合 OpenAI Daybreak 模型與自家網路流量資料,為開發者提供具生產脈絡的漏洞修補建議。
閱讀文章 ↗用 Zstandard 與 Pingora 節省 PB 級快取儲存:Cloudflare 的 Cache Transcoding 原型
Cloudflare 工程實習生打造 Cache Transcoding 原型,在 Pingora 快取內以 Zstandard 壓縮文字資產,用少量 CPU 換取可觀的儲存與跨資料中心頻寬節省。本文解析其取捨、設計與測試結果。
閱讀文章 ↗Adaptive Intelligence:讓每次攻擊都變得不划算
Cloudflare 推出 Adaptive Intelligence,從「假設攻擊者終會突破」出發,用持續學習與一次性規則扭轉攻防經濟學。
閱讀文章 ↗BotBase for Operators:讓網站主與機器人營運者不再互相猜測
Cloudflare 推出 BotBase for Operators,把機器人提交流程從黑箱變成透明可追蹤的儀表板,並用新的行為與內容使用分類法加速審核。
閱讀文章 ↗Bot Preference Sync:Cloudflare 把 AI 機器人政策寫回 robots.txt
Cloudflare 推出 Bot Preference Sync,把 AI 搜尋、代理、訓練的政策自動同步到 robots.txt。文章拆解運作方式、出版者預設,以及透明度要求。
閱讀文章 ↗OAuth 不再全有或全無:Cloudflare 推出可自訂的授權範圍
Cloudflare 推出 OAuth scope customization,讓使用者在同意畫面取消勾選 optional scopes,不再只能全有或全無;對 MCP 與 agent 類應用特別實用。
閱讀文章 ↗看不見的 Agent 流量:Cloudflare 如何偵測 Shadow MCP 並收回治理權
MCP 流量沒有保證的 hostname、也不需要 /mcp 路徑,企業網路裡的 agent 直連可能早已繞過所有核准流程。本文整理 Cloudflare 用 protocol signals 讓 MCP 流量現形的方法,以及先 visibility 再 enforcement 的治理順序。
閱讀文章 ↗用 Cloudflare Access 一次點擊,保護所有內部 vibe-coded 應用
Cloudflare 推出 Workers 層級的 Access 政策,讓企業可以預設所有內部應用都需登入,並直接在程式碼中取得使用者身份。
閱讀文章 ↗Cloudflare AI Search:為你的 Agent 加上一個專屬搜尋引擎
Cloudflare AI Search 推出開發者體驗更新,讓 Agent 能直接搜尋你的資料,並提供可預測的定價預覽。本文整理重點功能與實際應用案例。
閱讀文章 ↗把問題倒過來問:Agent Cloud 到底是為誰設計的?
Cloudflare 在 Agents Week 開幕文把 Agent Cloud 的定義權交給 agent:與其由人類替 agent 設想需求,不如直接問 agent 本身。本文拆解 agent-native primitives 與 translation layer 的雙軌任務、五天議程主軸、ask-your-agent 實驗的 prompt 框架,以及願景文的讀法與限制。
閱讀文章 ↗Cloudflare OAuth 全開放:自助式用戶端與零停機引擎升級
Cloudflare 於 6 月 24 日宣布自助式 OAuth 開放給所有客戶,第三方整合不再依賴 API Token,文章詳述 Hydra 引擎兩階段零停機遷移與 P95 延遲近乎減半的過程。
閱讀文章 ↗Cloudflare 臨時帳號讓 AI 代理免註冊直接部署
Cloudflare 推出臨時帳號:AI 代理執行 wrangler deploy --temporary 即可免帳號、免金鑰部署到 Workers,60 分鐘內可由人類認領,逾期自動刪除。本文解析流程、限制與安全模型。
閱讀文章 ↗Cloudflare Agent Cloud 引入 OpenAI 模型:企業部署代理的新基建
Cloudflare 與 OpenAI 合作,讓企業在 Agent Cloud 上直接使用 GPT-5.4 與 Codex,部署可執行真實工作的 AI 代理。
閱讀文章 ↗Cloudflare Markdown for Agents:把乾淨內容直接餵給 AI 代理
2026 年 2 月 12 日,Cloudflare 推出 Markdown for Agents:AI 代理在 Accept 標頭帶 text/markdown,邊緣就把 HTML 轉成 Markdown,token 最多省 80%,但 SEO 圈質疑形同 cloaking,Google 與 Bing 方公開表態。
閱讀文章 ↗GLM-4.7-Flash 上線 Cloudflare Workers AI:模型供應商與邊緣平台的組合拳
2026 年 2 月 13 日,智譜的 GLM-4.7-Flash 登上 Cloudflare Workers AI,同一波社群公告還帶來 agents-on-Cloudflare 工具與 Workers AI Provider v3.1.1。開源模型的部署版圖,正往 serverless 邊緣推理推進。
閱讀文章 ↗
2026
19 ARTICLESCatching JavaScript That Waits for the Right Victim
Cloudflare's Page Shield ML caught 8 payloads that scanners missed, showing why storefronts need runtime detection, not just static scans.
READ POST ↗Scoping Cloudflare Workers Access So Agents Can't Touch Production
Cloudflare adds per-Worker roles and scoped API tokens so teammates and agents get only the access they need.
READ POST ↗Cloudflare's Disallow AI Training Setting: What Changes for Your Crawl Policy
Cloudflare's new setting lets mixed-use crawlers keep indexing your site while refusing AI training use.
READ POST ↗Context-Aware Vulnerability Discovery: Cloudflare and OpenAI Daybreak
Cloudflare's new Vulnerability Discovery and Remediation service pairs OpenAI Daybreak models with network context to prioritize and patch code vulnerabilities.
READ POST ↗How Cloudflare Could Save Petabytes of Cache Storage with Zstandard and Pingora
Cloudflare's Cache Transcoding prototype compresses cache entries with Zstandard inside Pingora, trading a small CPU increase for significant storage and bandwidth savings.
READ POST ↗Adaptive Intelligence: Making Bot Attacks Too Expensive to Run
Cloudflare's new bot detection engine flips the economics of attacks by continuously retraining, using disposable rules, and learning from traffic—so attackers can't adapt faster than defenders.
READ POST ↗BotBase for Operators: Cloudflare Gives Bot Operators a Clearer Path to the Directory
Cloudflare's BotBase for Operators brings transparency to bot submissions: status tracking, editable entries, and a new taxonomy.
READ POST ↗Bot Preference Sync: Cloudflare Syncs Your AI Bot Policies to robots.txt
Cloudflare's Bot Preference Sync writes your AI bot settings to robots.txt, keeping stated preferences and enforced rules aligned. Learn how it works, publisher defaults, and…
READ POST ↗Cloudflare's Task-Based OAuth Consent: Moving Beyond All-or-Nothing Permissions
Cloudflare now lets users deselect optional OAuth scopes at consent time. Learn how it works, why it matters for MCP servers, and how to handle partial grants.
READ POST ↗Detecting Shadow MCP Traffic: How Cloudflare Brings Agent Tool Calls Under Governance
Learn how Cloudflare identifies MCP traffic on your network, distinguishes shadow MCP from portal bypass, and enforces governed access to AI agent tools.
READ POST ↗Secure All Your Internal Vibe-Coded Applications on Cloudflare Workers — in One Click
Cloudflare Access now applies directly to Workers or entire accounts, making internal apps private by default with easy identity access.
READ POST ↗Cloudflare AI Search: Give Your Agents a Search Engine for Your Data
Cloudflare AI Search updates: index websites, skip sitemaps, public endpoints, MCP support, and predictable pricing with free embedding and reranking.
READ POST ↗Flip the Question: Who Is Agent Cloud Actually Designed For?
Cloudflare's Agents Week opener hands the Agent Cloud definition to the agents themselves. Inside: the dual mandate, the five-day agenda, and the ask-your-agent experiment you can run today.
READ POST ↗Project Think: Cloudflare's New Primitives for Building AI Agents at Scale
Project Think moves the coding-agent loop—read, write, execute, remember—into a serverless model: zero-cost hibernation, recoverable fibers, 99.9% token savings, and a capability-based ladder.
READ POST ↗Cloudflare Opens Self-Managed OAuth to All Developers
Cloudflare opened self-managed OAuth to every customer on June 24, retiring the API-token workaround, after a zero-downtime Hydra engine upgrade that cut API P95 latency by 45%.
READ POST ↗Cloudflare Temporary Accounts: Agent Deploys Without Signup
Cloudflare lets AI agents deploy to Workers with no signup: wrangler deploy --temporary provisions a 60-minute account a human can claim, or it is auto-deleted.
READ POST ↗OpenAI Models Now Run Inside Cloudflare Agent Cloud: What Builders Should Know
OpenAI frontier models like GPT-5.4 are now available in Cloudflare Agent Cloud, with Codex harness in Sandboxes. Here's what it means for deploying AI agents.
READ POST ↗Cloudflare Markdown for Agents Serves AI the Clean Version
February 12, 2026: Cloudflare launched Markdown for Agents — an Accept text/markdown header gets HTML converted at the edge, cutting tokens up to 80%. SEOs warn of cloaking; Google and Bing objected.
READ POST ↗GLM-4.7-Flash Lands on Cloudflare Workers AI: A Model Supplier Meets an Edge Platform
On February 13, 2026, Zhipu's GLM-4.7-Flash arrived on Cloudflare Workers AI, with agents-on-Cloudflare tooling and Workers AI Provider v3.1.1 — open models push into serverless edge inference.
READ POST ↗