Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- The announcement offers basic API and dashboard access to every account. Free accounts can select one RSS feed, with derived private data retained for up to 30 days. Verify actual access and quotas.
- The dashboard path is Application Security, Threat Intelligence, then Threat Signals. Feed settings include name, category, and polling interval. Supported formats are RSS 2.0, Atom, and RSS 1.0/RDF.
- The system extracts indicators, summaries, and tags while linking threat events to original reports. Check source context and local traffic evidence before choosing a defensive action.
- API tokens need Cloudforce One permissions; feed creation and modification need write access. Free-tier feed and default-skill limits mean basic access does not include every API or customization.
- More feeds, proprietary datasets, custom skills, increased storage, and custom WAF rules based on events are enterprise extensions. Extracting indicators does not automatically block them on free accounts.
- PRODUCT_FIT=CONDITIONAL_NETWORK_ONLY: A proxy or fixed egress does not increase intelligence permissions or change WAF decisions. Investigate networking only for a separate dashboard or API connection failure.
What launched, and what do free accounts receive?
Cloudflare's September 29, 2026 announcement describes Threat Signals as generally available through API and dashboard. Each account can select one RSS feed to generate a private Threat Intelligence dataset, retain derived data for up to 30 days, and investigate related events, indicators, and tags in the Threat Events Platform. This is the announced scope, not a login-based verification of any particular account.
The announcement lists additional RSS feeds, proprietary Cloudforce One datasets, custom agentic skills, more storage, and custom WAF rules from open or proprietary events as enterprise extensions across Essentials, Advantage, and Elite. The API overview also notes Free feed quotas and managed-default-skill limits. Check the account's quotas and permissions before purchasing or configuring protection; basic access does not make advanced features free.
Start with one RSS feed whose reports you can verify
Open Application Security, Threat Intelligence, then Threat Signals in the Cloudflare dashboard. Choose an intelligence feed relevant to your organization's risks that consistently links original reports. Set a recognizable name, category, and polling interval. Cloudflare lists RSS 2.0, Atom, and RSS 1.0/RDF. With one free feed, evaluate content quality and update patterns before considering more.
After adding it, check retrieval, continuing article arrivals, and original-report links. Preserve publication times, sources, and investigation context with reports and indicators. An extracted IP or domain does not mean it should be blocked now. If summaries or tags differ from the report, verify the original and record false positives or omissions.
From articles to trustworthy indicators
Cloudflare's pipeline polls RSS articles, retrieves their bodies, extracts and normalizes indicators, summarizes and tags with default skills, then associates indicators with private Threat Events. Analysts can trace an indicator to its event and original report instead of viewing addresses without context.
Choose a known report and compare its summary, affected products, indicator types and values, tags, and references with the source. Then use your traffic logs, asset inventory, and event timeline to judge relevance. A domain mentioned in a report may be legitimate shared infrastructure or a historical sample. Do not automatically import extractions into a global blocklist or equate Threat Signals event counts with attack counts.
API access: Separate read and write permissions
The Threat Signals API overview requires a token with Cloudforce One permissions. Creating, modifying, or deleting feeds, skills, or tags needs write permission. Interfaces include categories, feed listing and creation, and article and indicator listing. Use minimum read permissions for verification and controlled write permission only when needed. Keep tokens out of articles and logs.
The official feed-creation endpoint is POST /accounts/{account_id}/cloudforce-one/v2/threat-signals/feeds. Read categories first where needed; documented fields include url, display_name, category_id, and poll_interval_s. This locates the interface rather than providing an executable example without verified account ID, permissions, and plan. Diagnose permission and quota errors separately from connection failures.
WAF protection needs a separate decision
Cloudflare says extracted indicators can inform WAF, but places custom WAF rules from threat events in enterprise extensions. Viewing events and indicators does not automatically create Block rules for every free account. Check source reliability, relevance to current assets, false-positive cost, and timeliness.
If the organization has the plan and permissions and decides to adjust WAF, first observe matches and legitimate traffic in a limited scope. A security owner should approve actions and define review and reversal conditions. For 403 responses, inspect Security Events, Ray ID, and actual rules rather than blaming a new feed by assumption. See Cloudflare WAF rules and false-positive troubleshooting.
PuppyIP's network troubleshooting boundary
Threat Signals plans, tokens, Cloudforce One permissions, feed quotas, and WAF rules are Cloudflare account settings. Changing a proxy or fixed egress does not increase permissions, correct intelligence false positives, or change an active security rule.
Consult the proxy connection checklist only for independent DNS failures, TCP timeouts, TLS handshake errors, or proxy 407 responses when accessing the dashboard or API. This guide uses public announcements and API documentation; it has not created feeds or tested quotas in reader accounts. Confirm actual features, retention, and permissions in current account settings and documentation.
Sources
Frequently Asked Questions
Can free Cloudflare accounts use Threat Signals?
The September 29 announcement offers basic access to all accounts, including one RSS feed and API/dashboard access. API documentation notes limits on Free feeds and default skills. Verify the account's entry points and permissions.
How long is data from the free feed retained?
The announcement says derived private intelligence data is retained for up to 30 days. Increased storage is an enterprise extension. Up to 30 days does not guarantee every item remains complete for 30 days.
Which feed formats are supported?
The announcement lists RSS 2.0, Atom, and RSS 1.0/RDF. Check actual retrieval, original article links, and update frequency after configuration.
What permission is needed to create a feed through the API?
Cloudforce One permissions and the relevant write access. Also check the feed quota, category, and target RSS URL.
Will extracted malicious IPs be blocked automatically?
Do not assume so. Basic features provide reports, events, and indicators; custom WAF rules from events are an enterprise extension. Protection and action require separate decisions about plan, permissions, sources, and false positives.
Can a fixed IP fix permissions or false positives?
No. Fixed egress does not add Cloudflare permissions or change indicator judgments. Investigate the network path only for separate DNS, TCP, TLS, or proxy 407 failures.