SendTech Times
News
SYSTEMS SHIFT:

Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent

Newsroom brief

Cloudflare made Precursor generally available to score visitor behaviour across full browser sessions rather than one arrival check. The public record still lacks pricing, customer adoption figures and customer false-positive rates for the session-scoring product.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: SiliconANGLE
Cloudflare Precursor Scores Browser Sessions As Bot Traffic Hits 57 Percent
Image source: SiliconANGLE

Cloudflare has made Precursor generally available, giving websites a browser-session bot detector at a time when automated traffic accounts for roughly 57 percent of web requests, SiliconANGLE reported.

Running inside a visitor's browser, the system streams interaction signals back to Cloudflare's edge, where servers score the session in real time for evidence of automation.

Precursor is designed to replace one-time CAPTCHA-style checks with continuing behavioural scoring.

Precursor Tracks Full Browser Sessions

Precursor follows behaviour across an entire visit rather than testing a user only once on arrival.

A challenge page checks the visitor at the door, while later actions are normally assumed to be legitimate.

In comments to SiliconANGLE, Cloudflare Chief Technology Officer Dane Knecht said the company is looking at behaviour over the whole visit instead of only checking an ID at the gate.

The tool is meant to make it harder for automated systems to pass a single check and then continue browsing with a clean status.

Bot Traffic Reaches 57 Percent Of Requests

SiliconANGLE cited Cloudflare's estimate that bot traffic makes up roughly 57 percent of web requests.

The outlet described the company's argument as automation now outweighing people online and single-action tests being easier for bots to imitate.

Precursor continues scoring after the initial page load.

Even if an automated agent tries to erase its behavioural signature by reloading a page under per-request challenges, the system keeps accumulating session context.

Browser Script Records Timing And Visibility Signals

Customers can turn on Precursor with one click and without code changes.

A small script is injected into pages already passing through Cloudflare's network, then logs mouse movement, scrolling rhythm, typing cadence, clipboard activity and the length of time a page stays visible in the browser tab.

The analysis engine checks for contradictions inside those signals.

Examples included pointer activity while a page is hidden and typing events at a moment when no text field has focus.

Cloudflare said the script records aggregate patterns rather than the typed inputs themselves.

Keyboard activity is stored as rhythm and cadence, while the characters typed are not captured, according to the company.

AI Scraper Controls Sit Behind The Launch

The launch follows earlier Cloudflare bot and crawler products.

Last year, it began blocking artificial intelligence scrapers by default for new customers and later built tools for publishers to set crawler access terms.

Knecht added that login and checkout are already covered by Cloudflare protections billions of times each day, while the activity between those events had remained a black box.

Precursor is generally available now, but the public record still lacks pricing, customer adoption figures and false-positive rates for the session-scoring product.

Share this article
inXf

Related articles

More
AI Patch Study Keeps Humans In Vulnerability Reviews
Cybersecurity

AI Patch Study Keeps Humans In Vulnerability Reviews

The Register reported that 1Password Off-by-1 Labs tested 6,080 AI-generated patches across six CVEs and found clean autonomous fixes in 26.0 percent of cases, leaving security teams with a supervision problem rather than a replacement for vulnerability review.

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished
Cybersecurity

Kratos Takedown Leaves Microsoft 365 Session-Theft Risk Unfinished

German and US law enforcement took more than 200 Kratos phishing-kit servers offline, but investigators still tie the service to roughly 1,800 customers and session-theft attacks against Microsoft 365.

Socket Tracks 108 Malicious Packages In PolinRider Supply-Chain Attack
Cybersecurity

Socket Tracks 108 Malicious Packages In PolinRider Supply-Chain Attack

Socket reported 162 malicious release artefacts across 108 packages in the PolinRider supply-chain campaign. Victim companies remain outside the public record.

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study
Cybersecurity

Unit 42 Finds 13,229 Malicious URLs In AI Phantom-Domain Study

Palo Alto Networks’ Unit 42 said its phantom-squatting research generated 685,339 prompts across 913 brands and produced 2.1 million unique URLs, including 13,229 malicious URLs and about 250,000 unique phantom domains. The public report did not disclose the brand list, affected customer names or named domains tied to data loss.

Minnesota Water Cyberattack Hits More Than 30 Systems
Cybersecurity

Minnesota Water Cyberattack Hits More Than 30 Systems

The Hacker News reported that Minnesota opened a statewide response after more than 30 community water systems were affected, with attribution and the access method still unconfirmed.

Elementor CSRF Flaw Exposes WordPress Sites to Link-Based Takeover
Cybersecurity

Elementor CSRF Flaw Exposes WordPress Sites to Link-Based Takeover

Elementor fixed a CSRF flaw in versions 4.3.0 and 4.3.1 that could let attackers abuse a logged-in WordPress administrator’s browser to create rogue admin accounts.

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion
Cybersecurity

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion

Hugging Face said an autonomous AI agent system drove an intrusion into part of its production infrastructure, reaching internal datasets and service credentials. The company said public models, datasets and Spaces were not tampered with, while its assessment of partner or customer data remains unfinished.

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk
Cybersecurity

Microsoft Revokes 11 Secure Boot Shims After ESET Finds Bypass Risk

Ars Technica reported that ESET found 11 old UEFI shim images that Microsoft still trusted even after known defects. Microsoft revoked the shims in its June patch release, while the reason the lapse lasted for years remains outside the public account.

Keep Reading

More Stories

Latest
Finland Halts Work at Two Google Data-Centre SitesEconomyOct 7, 2026Finland Halts Work at Two Google Data-Centre SitesFinland’s environmental supervisor ordered preparatory work to stop at Google-linked data-centre sites in Muhos and Kajaani while Tuike Finland answers questions over forest clearance and environmental assessment requirements.FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchAIOct 7, 2026FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchStealth AI research startup FYDY is negotiating a $12 million maiden round from Lightspeed Venture Partners and General Catalyst as it builds OpenScientist and a frontier AI team split across India and the US.The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.