Cloudflare has announced Vulnerability Discovery and Remediation, a new service designed to automate vulnerability discovery, generate code fixes, and deploy edge protections against active threats with human approval. The service uses OpenAI Daybreak models, a family of cyber defense models that includes GPT-5.6 Cyber.
The new service offers automatic vulnerability scans, recommends remediation actions, and lets your team make the final call on whether to implement the proposed solution.
Matthew Prince, co-founder and CEO of Cloudflare, had this to say: “If your security team is manually fighting AI-driven attacks, you’re not just burning them out—you’re losing. Now, we’re shifting the defense strategy away from chasing patches one vulnerability at a time to an automated approach.”
The service is currently in early access and available by invitation to select Cloudflare Enterprise customers through the Cloudflare Managed Defense (CMD) platform.
What this new offering brings
This platform is currently in early access, meaning that only a few selected enterprises can access it through the Cloudflare Managed Defense (CMD) platform.
CMD uses Cloudflare engineers to monitor threats for subscribed customers and respond to them 24/7. According to the Service Level Agreement (SLA), customers can expect an incident response within less than 30 minutes.
Cloudflare Managed Defense combines the company’s security technology with human analysts who monitor threats and respond to incidents for customers around the clock.
This recent development now adds agentic actors to the list of defenders on CMD.
According to the company’s engineers, they have overhauled the TIP to “eliminate the need for complex ETL (Extract, Transform, Load) pipelines by using a sharded, SQLite-backed architecture.”
The implication is that each logical shard can now be autonomously evaluated for security vulnerabilities at the edge in sub-seconds.
The changing landscape
A day prior to the Vulnerability Discovery and Remediation launch, one of the largest cloud security platforms, CrowdStrike, also announced that it had extended its enterprise security to Codex agents and also brought OpenAI’s GPT-5.6 Cyber to the Falcon platform.
The CrowdStrike service is more than just using autonomous actors to defend existing resources; it’s also about monitoring and enforcing security controls for them. The goal is to respond to security threats created by agents used by the enterprise and by external ones attacking it.
This shift by some of the internet’s biggest security providers in setting up enterprise security operations centers (SOCs) is a signal of how AI agents are forcing enterprises to adjust their security posture.
“Status quo security is no longer enough, but AI gives defenders a real opportunity to become fundamentally stronger,” said Greg Brockman, President and Co-founder of OpenAI.
For security leaders, that creates two related challenges: using automation to respond faster without surrendering too much control, and making sure the agents introduced to strengthen security do not create another layer of risk themselves.
Other news: Security teams are being urged to move beyond CVSS scores and prioritize flaws using exploitability, asset context, attack paths, and AI-driven analysis.





