logo

From reactive to proactive: closing the phishing gap with LLMs

ID: 7e02ed05-09b4-5c32-b900-5aebb9599981

STIX ID: report--7e02ed05-09b4-5c32-b900-5aebb9599981

Feed Name: Cloudflare Blog

Date Published: 2026-03-03

Date Updated: 2026-04-27

Author: Sebastian Alovisi

...
...

**Executive Summary:** This Cloudflare report explains how integrating large language models into email security enables proactive discovery and characterization of phishing (notably Sales Outreach–style B2B phishing), describes a pipeline that uses LLM-generated tags to build targeted training data and specialized sentiment/intent models, summarizes measurable improvements (a reported 20.4% reduction in Sales Outreach user-reported misses from Q3 to Q4 2025 and continued declines into Q1 2026), and highlights the Retro Scan tool for organizations to scan Microsoft 365 inboxes and remediate threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.