Cloudflare's postmortem preserves the wrong answer, in their own words:
"In the initial moments of the outage there was speculation it was an attack of some type we'd never seen before."
That belief owns the 13:45–14:00 window — fifteen minutes, most of the diagnostic time in a 27-minute outage. What ended it was the Performance team's live CPU data and strace, which showed the WAF process itself burning the CPU rather than straining under external traffic.
The reason this note matters is that the hypothesis was correct reasoning from the available evidence. CPU saturating to ~100% simultaneously across every edge machine on the planet is what a novel volumetric attack looks like. Nothing visible at 13:45 distinguished "we are being attacked" from "we attacked ourselves six minutes ago." A responder who reached for the attack explanation was not being careless; they were being sensible with the signal they had.
So the note carries three things: what was believed (a novel attack), what ruled it out (CPU attributed to the WAF process, via live profiling), and whether the misleading signal is still there — which is the part that turns a dead end into work. A global CPU spike will look like an attack during the next incident too, unless something in the dashboard distinguishes "our process is spending it" from "we are receiving more of it."
Notice what had to happen for you to be reading this at all: someone chose to publish the embarrassing fifteen minutes. Most postmortems compress that interval to a sentence, and the sentence is where the value was.