Website Security & Threat Management
From reactive to proactive: closing the phishing gap with LLMs

From reactive to proactive: closing the phishing gap with LLMs

3/3/2026 · Sebastian Alovisi, Ayush Kumar

What this post added

This post details the integration of Large Language Models (LLMs) into Cloudflare's email security tools to proactively identify and categorize phishing threats. It describes how LLMs are used to analyze millions of emails daily, extracting nuanced threat vectors like 'Sales Outreach' and 'PrizeNotification'. This enables the creation of high-fidelity signals for analysts and the development of specialized machine learning models trained on LLM-generated tags. The post highlights a 20.4% reduction in customer-reported misses for Sales Outreach phishing in Q4 2025 due to this proactive approach, demonstrating a shift from reactive defense to proactive reinforcement.

Read the original post ↗