Generic CC0 editorial illustration

We built a WAF tester that adapted each request based on what the WAF blocked or passed. This helped us explore variations that a fixed test might miss. We ran it across six attack categories on an authorized staging environment and discovered detection gaps worth fixing. Here’s how the loop worked, what got through, and what we did about it.

Editorial note. This page preserves feed metadata and a bounded excerpt for discovery. It does not reproduce the publisher's complete article.

Open the complete publication at Cloudflare Blog →

Record details

  • Local record: 4e49e0b028a2088661f7
  • Source feed: Cloudflare Blog
  • Published: 2026-09-29T13:00:00Z