Pular para o conteúdo

Changelog

New updates and improvements at Cloudflare.

Dismiss and filter matches in Brand Protection

We have introduced new triage controls to help you manage your Brand Protection results more efficiently. You can now clear out the noise by dismissing matches while maintaining full visibility into your historical decisions.

What's new

  • Dismiss matches: Users can now mark specific results as dismissed if they are determined to be benign or false positives, removing them from the primary triage view.
  • Show/Hide toggle: A new visibility control allows you to instantly switch between viewing only active matches and including previously dismissed ones.
  • Persistent review states: Dismissed status is saved across sessions, ensuring that your workspace remains organized and focused on new or high-priority threats.

Key benefits of the dismiss match functionality:

  • Reduce alert fatigue by hiding known-safe results, allowing your team to focus exclusively on unreviewed or high-risk infringements.
  • Auditability and recovery through the visibility toggle, ensuring that no match is ever truly "lost" and can be re-evaluated if a site's content changes.
  • Improved collaboration as your team members can see which matches have already been vetted and dismissed by others.

Ready to clean up your match queue? Learn more in our Brand Protection documentation.

Post-Quantum Encryption and Key Transparency on Cloudflare Radar

Radar now tracks post-quantum encryption support on origin servers, provides a tool to test any host for post-quantum compatibility, and introduces a Key Transparency dashboard for monitoring end-to-end encrypted messaging audit logs.

Post-quantum origin support

The new Post-Quantum API provides the following endpoints:

The new Post-Quantum Encryption page shows the share of customer origins supporting X25519MLKEM768, derived from daily automated TLS scans of TLS 1.3-compatible origins. The scanner tests for algorithm support rather than the origin server's configured preference.

Screenshot of the origin post-quantum support graph on Radar

A host test tool allows checking any publicly accessible website for post-quantum encryption compatibility. Enter a hostname and optional port to see whether the server negotiates a post-quantum key exchange algorithm.

Screenshot of the post-quantum host test tool on Radar

Key Transparency

A new Key Transparency section displays the audit status of Key Transparency logs for end-to-end encrypted messaging services. The page launches with two monitored logs: WhatsApp and Facebook Messenger Transport.

Each log card shows the current status, last signed epoch, last verified epoch, and the root hash of the Auditable Key Directory tree. The data is also available through the Key Transparency Auditor API.

Screenshot of the Key Transparency dashboard on Radar

Learn more about these features in our blog post and check out the Post-Quantum Encryption and Key Transparency pages to explore the data.

RPKI ASPA Deployment Insights on Cloudflare Radar

Radar now includes Autonomous System Provider Authorization (ASPA) deployment insights, providing visibility into the adoption and verification of ASPA objects across the global routing ecosystem.

New API endpoints

The new ASPA API provides the following endpoints:

New Radar widgets

The global routing page now shows the ASPA deployment trend over time by counting daily ASPA objects.

Screenshot of the ASPA deployment trend chart

The global routing page also displays the most recent ASPA objects, searchable by ASN or AS name.

Screenshot of the ASPA objects table

On country and region routing pages, a new widget shows the ASPA deployment rate for ASNs registered in the selected country or region.

Screenshot of the ASPA deployment trent chart for Germany

On AS routing pages, the connectivity table now includes checkmarks for ASPA-verified upstreams. All ASPA upstreams are listed in a dedicated table, and a timeline shows ASPA changes at daily granularity.

Screenshot of the ASPA changes timeline on an AS routing page

Check out the Radar routing page to explore the data.

Saved views for Threat Events

TL;DR: You can now create and save custom configurations of the Threat Events dashboard, allowing you to instantly return to specific filtered views — such as industry-specific attacks or regional Sankey flows — without manual reconfiguration.

Why this matters

Threat intelligence is most effective when it is personalized. Previously, analysts had to manually re-apply complex filters (like combining specific industry datasets with geographic origins) every time they logged in. This update provides material value by:

  • Analysts can now jump straight into "Known Ransomware Infrastructure" or "Retail Sector Targets" views with a single click, eliminating repetitive setup tasks
  • Teams can ensure everyone is looking at the same data subsets by using standardized saved views, reducing the risk of missing critical patterns due to inconsistent filtering.

Cloudforce One subscribers can start saving their custom views now in Application Security > Threat Intelligence > Threat Events.

DEX Supports EU Customer Metadata Boundary

Digital Experience Monitoring (DEX) provides visibility into WARP device connectivity and performance to any internal or external application.

Now, all DEX logs are fully compatible with Cloudflare's Customer Metadata Boundary (CMB) setting for the 'EU' (European Union), which ensures that DEX logs will not be stored outside the 'EU' when the option is configured.

If a Cloudflare One customer using DEX enables CMB 'EU', they will not see any DEX data in the Cloudflare One dashboard. Customers can ingest DEX data via LogPush, and build their own analytics and dashboards.

If a customer enables CMB in their account, they will see the following message in the Digital Experience dashboard: "DEX data is unavailable because Customer Metadata Boundary configuration is on. Use Cloudflare LogPush to export DEX datasets."

Digital Experience Monitoring message when Customer Metadata Boundary for the EU is enabled

Cloudforce One Threat events graphs are now visible in the dashboard

We have introduced dynamic visualizations to the Threat Events dashboard to help you better understand the threat landscape and identify emerging patterns at a glance.

What's new:

  • Sankey Diagrams: Trace the flow of attacks from country of origin to target country to identify which regions are being hit hardest and where the threat infrastructure resides.
Sankey Diagram
  • Dataset Distribution over time: Instantly pivot your view to understand if a specific campaign is targeting your sector or if it is a broad-spectrum commodity attack.
Events over time
  • Enhanced Filtering: Use these visual tools to filter and drill down into specific attack vectors directly from the charts.

Cloudforce One subscribers can explore these new views now in Application Security > Threat Intelligence > Threat Events.

New cfWorker metric in Server-Timing header

The Server-Timing header now includes a new cfWorker metric that measures time spent executing Cloudflare Workers, including any subrequests performed by the Worker. This helps developers accurately identify whether high Time to First Byte (TTFB) is caused by Worker processing or slow upstream dependencies.

Previously, Worker execution time was included in the edge metric, making it harder to identify true edge performance. The new cfWorker metric provides this visibility:

Metric Description
edge Total time spent on the Cloudflare edge, including Worker execution
origin Time spent fetching from the origin server
cfWorker Time spent in Worker execution, including subrequests but excluding origin fetch time

Example response

Server-Timing: cdn-cache; desc=DYNAMIC, edge; dur=20, origin; dur=100, cfWorker; dur=7

In this example, the edge took 20ms, the origin took 100ms, and the Worker added just 7ms of processing time.

Availability

The cfWorker metric is enabled by default if you have Real User Monitoring (RUM) enabled. Otherwise, you can enable it using Rules.

This metric is particularly useful for:

  • Performance debugging: Quickly determine if latency is caused by Worker code, external API calls within Workers, or slow origins.
  • Optimization targeting: Identify which component of your request path needs optimization.
  • Real User Monitoring (RUM): Access detailed timing breakdowns directly from response headers for client-side analytics.

For more information about Server-Timing headers, refer to the W3C Server Timing specification.

Cloudflare One Product Name Updates

We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.

We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.

What's changing

  • Magic WANCloudflare WAN
  • Magic WAN IPsecCloudflare IPsec
  • Magic WAN GRECloudflare GRE
  • Magic WAN ConnectorCloudflare One Appliance
  • Magic FirewallCloudflare Network Firewall
  • Magic Network MonitoringNetwork Flow
  • Magic Cloud NetworkingCloudflare One Multi-cloud Networking

No action is required by you — all functionality, existing configurations, and billing will remain exactly the same.

For more information, visit the Cloudflare One documentation.

Content Type Dimension for AI Bots in Cloudflare Radar

Radar now includes content type insights for AI bot and crawler traffic. The new content_type dimension and filter shows the distribution of content types returned to AI crawlers, grouped by MIME type category.

The content type dimension and filter are available via the following API endpoints:

Content type categories:

  • HTML - Web pages (text/html)
  • Images - All image formats (image/*)
  • JSON - JSON data and API responses (application/json, *+json)
  • JavaScript - Scripts (application/javascript, text/javascript)
  • CSS - Stylesheets (text/css)
  • Plain Text - Unformatted text (text/plain)
  • Fonts - Web fonts (font/*, application/font-*)
  • XML - XML documents and feeds (text/xml, application/xml, application/rss+xml, application/atom+xml)
  • YAML - Configuration files (text/yaml, application/yaml)
  • Video - Video content and streaming (video/*, application/ogg, *mpegurl)
  • Audio - Audio content (audio/*)
  • Markdown - Markdown documents (text/markdown)
  • Documents - PDFs, Office documents, ePub, CSV (application/pdf, application/msword, text/csv)
  • Binary - Executables, archives, WebAssembly (application/octet-stream, application/zip, application/wasm)
  • Serialization - Binary API formats (application/protobuf, application/grpc, application/msgpack)
  • Other - All other content types

Additionally, individual bot information pages now display content type distribution for AI crawlers that exist in both the Verified Bots and AI Bots datasets.

Screenshot of the Content Type Distribution chart on the AI Insights page

Check out the AI Insights page to explore the data.

Enhanced Logo Matching for Brand Protection

We have significantly upgraded our Logo Matching capabilities within Brand Protection. While previously limited to approximately 100% matches, users can now detect a wider range of brand assets through a redesigned matching model and UI.

What's new

  • Configurable match thresholds: Users can set a minimum match score (starting at 75%) when creating a logo query to capture subtle variations or high-quality impersonations.
  • Visual match scores: Allow users to see the exact percentage of the match directly in the results table, highlighted with color-coded lozenges to indicate severity.
  • Direct logo previews: Available in the Cloudflare dashboard — similar to string matches — to verify infringements at a glance.

Key benefits

  • Expose sophisticated impersonators who use slightly altered logos to bypass basic detection filters.
  • Faster triage of the most relevant threats immediately using visual indicators, reducing the time spent manually reviewing matches.

Ready to protect your visual identity? Learn more in our Brand Protection documentation.

Tabs and pivots

Log Explorer now supports multiple concurrent queries with the new Tabs feature. Work with multiple queries simultaneously and pivot between datasets to investigate malicious activity more effectively.

Key capabilities

  • Multiple tabs: Open and switch between multiple query tabs to compare results across different datasets.
  • Quick filtering: Select the filter button from query results to add a value as a filter to your current query.
  • Pivot to new tab: Use Cmd + click on the filter button to start a new query tab with that filter applied.
  • Preserved progress: Your query progress is preserved on each tab if you navigate away and return.

For more information, refer to the Log Explorer documentation.

Threat actor identification with "also known as" aliases

Identifying threat actors can be challenging, because naming conventions often vary across the security industry. To simplify your research, Cloudflare Threat Events now include an Also known as field, providing a list of common aliases and industry-standard names for the groups we track.

This new field is available in both the Cloudflare dashboard and via the API. In the dashboard, you can view these aliases by expanding the event details side panel (under the Attacker field) or by adding it as a column in your configurable table view.

Key benefits

  • Easily map Cloudflare-tracked actors to the naming conventions used by other vendors without manual cross-referencing.
  • Quickly identify if a detected threat actor matches a group your team is already monitoring via other intelligence feeds.

For more information on how to access this data, refer to the Threat Events API documentation.

Network Services navigation update

The Network Services menu structure in Cloudflare's dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.

Your existing configurations will remain the same, and you will have access to all of the same features and functionality.

The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to Magic Transit, Magic WAN, and Magic Firewall.

Summary of changes:

  • A new Overview page provides access to the most common tasks across Magic Transit and Magic WAN.
  • Product names have been removed from top-level navigation.
  • Magic Transit and Magic WAN configuration is now organized under Routes and Connectors. For example, you will find IP Prefixes under Routes, and your GRE/IPsec Tunnels under Connectors.
  • Magic Firewall policies are now called Firewall Policies.
  • Magic WAN Connectors and Connector On-Ramps are now referenced in the dashboard as Appliances and Appliance profiles. They can be found under Connectors > Appliances.
  • Network analytics, network health, and real-time analytics are now available under Insights.
  • Packet Captures are found under Insights > Diagnostics.
  • You can manage your Sites from Insights > Network health.
  • You can find Magic Network Monitoring under Insights > Network flow.

If you would like to provide feedback, complete this form. You can also find these details in the January 7, 2026 email titled [FYI] Upcoming Network Services Dashboard Navigation Update.

Preview: Networking Navigation

URL Scanner now supports PDF report downloads

We have expanded the reporting capabilities of the Cloudflare URL Scanner. In addition to existing JSON and HAR exports, users can now generate and download a PDF report directly from the Cloudflare dashboard. This update streamlines how security analysts can share findings with stakeholders who may not have access to the Cloudflare dashboard or specialized tools to parse JSON and HAR files.

Key Benefits:

  • Consolidate scan results, including screenshots, security signatures, and metadata, into a single, portable document
  • Easily share professional-grade summaries with non-technical stakeholders or legal teams for faster incident response

What’s new:

  • PDF Export Button: A new download option is available in the URL Scanner results page within the Cloudflare dashboard
  • Unified Documentation: Access all scan details—from high-level summaries to specific security flags—in one offline-friendly file

To get started with the URL Scanner and explore our reporting capabilities, visit the URL Scanner API documentation.


Cloudflare Threat Events now support STIX2 format

We are excited to announce that Cloudflare Threat Events now supports the STIX2 (Structured Threat Information Expression) format. This was a highly requested feature designed to streamline how security teams consume and act upon our threat intelligence.

By adopting this industry-standard format, you can now integrate Cloudflare's threat events data more effectively into your existing security ecosystem.

Key benefits

  • Eliminate the need for custom parsers, as STIX2 allows for "out of the box" ingestion into major Threat Intel Platforms (TIPs), SIEMs, and SOAR tools.

  • STIX2 provides a standardized way to represent relationships between indicators, sightings, and threat actors, giving your analysts a clearer picture of the threat landscape.

For technical details on how to query events using this format, please refer to our Threat Events API Documentation.


Workers Analytics Engine SQL now supports filtering using HAVING and LIKE

You can now use the HAVING clause and LIKE pattern matching operators in Workers Analytics Engine.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale and query your data through a simple SQL API.

Filtering using HAVING

The HAVING clause complements the WHERE clause by enabling you to filter groups based on aggregate values. While WHERE filters rows before aggregation, HAVING filters groups after aggregation is complete.

You can use HAVING to filter groups where the average exceeds a threshold:

SELECT
    blob1 AS probe_name,
    avg(double1) AS average_temp
FROM temperature_readings
GROUP BY probe_name
HAVING average_temp > 10

You can also filter groups based on aggregates such as the number of items in the group:

SELECT
    blob1 AS probe_name,
    count() AS num_readings
FROM temperature_readings
GROUP BY probe_name
HAVING num_readings > 100

Pattern matching using LIKE

The new pattern matching operators enable you to search for strings that match specific patterns using wildcard characters:

  • LIKE - case-sensitive pattern matching
  • NOT LIKE - case-sensitive pattern exclusion
  • ILIKE - case-insensitive pattern matching
  • NOT ILIKE - case-insensitive pattern exclusion

Pattern matching supports two wildcard characters: % (matches zero or more characters) and _ (matches exactly one character).

You can match strings starting with a prefix:

SELECT *
FROM logs
WHERE blob1 LIKE 'error%'

You can also match file extensions (case-insensitive):

SELECT *
FROM requests
WHERE blob2 ILIKE '%.jpg'

Another example is excluding strings containing specific text:

SELECT *
FROM events
WHERE blob3 NOT ILIKE '%debug%'

Ready to get started?

Learn more about the HAVING clause or pattern matching operators in the Workers Analytics Engine SQL reference documentation.

Improved accuracy of cached request classification in analytics

The cached/uncached classification logic used in Zone Overview analytics has been updated to improve accuracy.

Previously, requests were classified as "cached" based on an overly broad condition that included blocked 403 responses, Snippets requests, and other non-cache request types. This caused inflated cache hit ratios — in some cases showing near-100% cached — and affected approximately 15% of requests classified as cached in rollups.

The condition has been removed from the Zone Overview page. Cached/uncached classification now aligns with the heuristics used in HTTP Analytics, so only requests genuinely served from cache are counted as cached.

What changed:

  • Zone Overview — Cache ratios now reflect actual cache performance.
  • HTTP Analytics — No change. HTTP Analytics already used the correct classification logic.
  • Historical data — This fix applies to new requests only. Previously logged data is not retroactively updated.

Cloud Services Observability in Cloudflare Radar

Radar introduces HTTP Origins insights, providing visibility into the status of traffic between Cloudflare's global network and cloud-based origin infrastructure.

The new Origins API provides provides the following endpoints:

  • /origins - Lists all origins (cloud providers and associated regions).
  • /origins/{origin} - Retrieves information about a specific origin (cloud provider).
  • /origins/timeseries - Retrieves normalized time series data for a specific origin, including the following metrics:
    • REQUESTS: Number of requests
    • CONNECTION_FAILURES: Number of connection failures
    • RESPONSE_HEADER_RECEIVE_DURATION: Duration of the response header receive
    • TCP_HANDSHAKE_DURATION: Duration of the TCP handshake
    • TCP_RTT: TCP round trip time
    • TLS_HANDSHAKE_DURATION: Duration of the TLS handshake
  • /origins/summary - Retrieves HTTP requests to origins summarized by a dimension.
  • /origins/timeseries_groups - Retrieves timeseries data for HTTP requests to origins grouped by a dimension.

The following dimensions are available for the summary and timeseries_groups endpoints:

  • region: Origin region
  • success_rate: Success rate of requests (2XX versus 5XX response codes)
  • percentile: Percentiles of metrics listed above

Additionally, the Annotations and Traffic Anomalies APIs have been extended to support origin outages and anomalies, enabling automated detection and alerting for origin infrastructure issues.

Screenshot of the cloud service status heatmap

Check out the new Radar page.

Threat insights are now available in the Threat Events platform

The threat events platform now has threat insights available for some relevant parent events. Threat intelligence analyst users can access these insights for their threat hunting activity. Insights are also highlighted in the Cloudflare dashboard by a small lightning icon and the insights can refer to multiple, connected events, potentially part of the same attack or campaign and associated with the same threat actor.

For more information, refer to Analyze threat events.

Fixed custom SQL date picker inconsistencies

We've resolved a bug in Log Explorer that caused inconsistencies between the custom SQL date field filters and the date picker dropdown. Previously, users attempting to filter logs based on a custom date field via a SQL query sometimes encountered unexpected results or mismatching dates when using the interactive date picker.

This fix ensures that the custom SQL date field filters now align correctly with the selection made in the date picker dropdown, providing a reliable and predictable filtering experience for your log data. This is particularly important for users creating custom log views based on time-sensitive fields.

Log Explorer adds 14 new datasets

We've significantly enhanced Log Explorer by adding support for 14 additional Cloudflare product datasets.

This expansion enables Operations and Security Engineers to gain deeper visibility and telemetry across a wider range of Cloudflare services. By integrating these new datasets, users can now access full context to efficiently investigate security incidents, troubleshoot application performance issues, and correlate logged events across different layers (like application and network) within a single interface. This capability is crucial for a complete and cohesive understanding of event flows across your Cloudflare environment.

The newly supported datasets include:

Zone Level

  • Dns_logs
  • Nel_reports
  • Page_shield_events
  • Spectrum_events
  • Zaraz_events

Account Level

  • Audit Logs
  • Audit_logs_v2
  • Biso_user_actions
  • DNS firewall logs
  • Email_security_alerts
  • Magic Firewall IDS
  • Network Analytics
  • Sinkhole HTTP
  • ipsec_logs

Example: Correlating logs

You can now use Log Explorer to query and filter with each of these datasets. For example, you can identify an IP address exhibiting suspicious behavior in the FW_event logs, and then instantly pivot to the Network Analytics logs or Access logs to see its network-level traffic profile or if it bypassed a corporate policy.

To learn more and get started, refer to the Log Explorer documentation and the Cloudflare Logs documentation.

DEX Logpush jobs

Digital Experience Monitoring (DEX) provides visibility into WARP device metrics, connectivity, and network performance across your Cloudflare SASE deployment.

We've released four new WARP and DEX device data sets that can be exported via Cloudflare Logpush. These Logpush data sets can be exported to R2, a cloud bucket, or a SIEM to build a customized logging and analytics experience.

  1. DEX Application Tests
  2. DEX Device State Events
  3. WARP Config Changes
  4. WARP Toggle Changes

To create a new DEX or WARP Logpush job, customers can go to the account level of the Cloudflare dashboard > Analytics & Logs > Logpush to get started.

DEX logpush job creation dashboard

More SQL aggregate, date and time functions available in Workers Analytics Engine

You can now perform more powerful queries directly in Workers Analytics Engine with a major expansion of our SQL function library.

Workers Analytics Engine allows you to ingest and store high-cardinality data at scale (such as custom analytics) and query your data through a simple SQL API.

Today, we've expanded Workers Analytics Engine's SQL capabilities with several new functions:

New aggregate functions:

  • countIf() - count the number of rows which satisfy a provided condition
  • sumIf() - calculate a sum from rows which satisfy a provided condition
  • avgIf() - calculate an average from rows which satisfy a provided condition

New date and time functions:

  • toYear()
  • toMonth()
  • toDayOfMonth()
  • toDayOfWeek()
  • toHour()
  • toMinute()
  • toSecond()
  • toStartOfYear()
  • toStartOfMonth()
  • toStartOfWeek()
  • toStartOfDay()
  • toStartOfHour()
  • toStartOfFifteenMinutes()
  • toStartOfTenMinutes()
  • toStartOfFiveMinutes()
  • toStartOfMinute()
  • today()
  • toYYYYMM()

Ready to get started?

Whether you're building usage-based billing systems, customer analytics dashboards, or other custom analytics, these functions let you get the most out of your data. Get started with Workers Analytics Engine and explore all available functions in our SQL reference documentation.