-

Orca Security Advances AI-First Cloud Defense with Autonomous Agents and Runtime AI Threat Detection

Ahead of RSAC 2026, Orca Security unveils new AI-driven capabilities that help organizations cut through alert noise, accelerate investigations, and focus on the risks that truly impact multi-cloud and AI environments

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, the pioneer of agentless cloud security, today announced major enhancements to the Orca Platform, introducing new AI-powered security agents, real-time detection of AI usage across cloud environments, remediation-focused workflows, and code reachability analysis. These innovations enable organizations to move beyond fragmented alerts to faster investigation, clearer prioritization, and measurable risk reduction in the AI-era.

As enterprises accelerate AI adoption and scale across multi-cloud environments, security teams are inundated with alerts yet lack the context and prioritization needed to distinguish real, business-critical risk from background noise. Research shows that 84% of organizations now run AI workloads in the cloud, and 62% already have vulnerable AI packages in their environments. Orca’s latest innovations extend its unified platform to help teams understand threats faster, focus on truly exploitable vulnerabilities, and take action with confidence.

“Security teams don’t need more data. They need to know what actually matters and what to do about it,” said Gil Geron, CEO and co-founder of Orca Security. “These new capabilities are designed to turn complex cloud risk into clear, actionable guidance so teams can make faster decisions and reduce exposure in a measurable way. That shift from information to action is what ultimately improves security outcomes.”

New platform capabilities include:

  • Threat Investigation Agent: Orca’s Threat Investigation Agent automatically analyzes risk, correlates signals across the cloud environment, and produces transparent investigation reports with recommended containment actions.
  • AppSec Triage Agent: The new AppSec Triage Agent analyzes SAST findings to identify false positives, reduce alert fatigue, and help teams focus on real vulnerabilities.
  • Runtime AI Threat Detection: Orca now identifies when workloads, identities, and processes interact with AI models, MCP servers, and third-party AI tools. This enables security teams to understand how AI is being used, detect potential exposure of sensitive data, and implement AI governance based on real runtime activity.
  • Orca Missions: Orca groups related findings into Missions—focused remediation initiatives with clear objectives and verification—allowing teams to resolve clusters of risk efficiently and track meaningful improvements in their security posture.
  • Code Reachability Analysis: Orca now analyzes whether vulnerable code paths are actually invoked in applications, in addition to identifying vulnerable packages. Combined with Orca’s existing Agentless and Dynamic Reachability Analysis, this provides comprehensive context to help teams prioritize vulnerabilities that are truly exploitable.

These enhancements build on Orca’s agentless-first architecture, which provides deep visibility and risk prioritization across cloud infrastructure, workloads, identities, applications, and now AI systems, without requiring agents.

“Cloud security tools generate an incredible amount of data, but what teams really need is help understanding what to do next,” said Erika Voss, SVP, Chief Security Officer at Blue Yonder. “What stands out about Orca is the way it connects the dots. Instead of spending hours piecing together alerts, our team can see what actually happened, what’s exposed, and where to focus first.”

Orca Security will showcase these new capabilities at RSA Conference 2026 in San Francisco. Attendees can visit Orca at Booth #1035 in the South Hall of Moscone Center to see live demonstrations.

About Orca Security
Orca enables organizations to make cloud security a strategic advantage. With the most comprehensive coverage and visibility across multi-cloud environments, the agentless-first Orca Platform unites teams to eliminate complexities, vulnerabilities and risks. Backed by Temasek, CapitalG, ICONIQ Capital, Redpoint Ventures and others, Orca is trusted by hundreds of organizations, including SAP, Gannett, Autodesk, Lemonade and Digital Turbine. Connect your first account in minutes: https://orca.security or book a personalized demo.

Contacts

Kaileigh Higgins
orcasecurity@inkhouse.com.

Orca Security


Release Versions

Contacts

Kaileigh Higgins
orcasecurity@inkhouse.com.

More News From Orca Security

Orca Security Signs Strategic Collaboration Agreement with AWS to Advance AI-Powered Cloud Security

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, a leader in agentless cloud security, today announced it has signed a strategic collaboration agreement (SCA) with Amazon Web Services (AWS) to help organizations strengthen their cloud security posture and accelerate innovation using AI-powered security solutions. As customers deploy AI-driven services and applications on AWS, security teams need deeper visibility into how AI workloads are built, configured, and used, along with faster, more inte...

Orca Security Appoints Rachel Nislick as Chief Marketing Officer

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, the pioneer of agentless cloud security, today announced the appointment of Rachel Nislick as Chief Marketing Officer. Nislick brings more than 25 years of experience building and scaling global marketing organizations for some of the most recognized companies in cybersecurity. Nislick will lead Orca’s global marketing strategy, driving brand, demand generation, product marketing and communications as the company continues to expand its AI-powered...

Orca Security Expands Strategic Partnership with Zscaler to Strengthen Zero Trust and Cloud Risk Management

PORTLAND, Ore.--(BUSINESS WIRE)--Orca Security, the pioneer in agentless cloud security, today announced an expanded strategic partnership with Zscaler, the leader in cloud security, that unites Zscaler Private Access™ (ZPA™) with Orca’s AI-powered cloud risk intelligence. The integration delivers unified visibility across cloud workloads and access infrastructure, helping organizations eliminate noise, prioritize critical risks, and strengthen their Zero Trust posture. As enterprises embrace c...
Back to Newsroom