
6/8/2026 · Alexandra Moraru, Harsh Saxena, Georgie Yoxall, Brian Seel
What this post added
Introduces a new integration that allows WAF rules to be written using live threat intelligence data. This enables proactive blocking of known bad actors, threat actors targeting specific industries or countries, and specific attack types by populating specialized fields during request processing. The feature leverages an always-on detection framework and provides O(1) constant-time lookups against compressed threat intelligence datasets distributed globally. New WAF fields like `cf.intel.ip.attacker_names`, `cf.intel.ip.target_industries`, `cf.intel.ip.attacker_countries`, and `cf.intel.ip.target_countries` are exposed to the WAF engine. The post also details how these fields integrate with the WAF rule builder (API & Terraform), Security Analytics, and the Threat Events dashboard for rule creation.