Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

Microsoft's CNAPP Recognition Highlights the Shift Toward Unified Cloud and AI Security

Microsoft's CNAPP Recognition Highlights the Shift Toward Unified Cloud and AI Security
Photo by Ryutaro Tsukata on Pexels

Microsoft says KuppingerCole has named it a leader across all four categories in its latest Cloud Native Application Protection Platform assessment. The announcement reflects a broader change in cloud security, with enterprises seeking unified visibility across infrastructure, workloads, identities, data, applications and AI systems.

News Date: 2026-08-05

Microsoft has been named a leader in KuppingerCole's latest assessment of Cloud Native Application Protection Platforms, receiving recognition in the Overall, Product, Innovation and Market categories. Although vendor rankings should always be considered alongside independent testing and customer requirements, the announcement illustrates how quickly the CNAPP market is expanding beyond conventional cloud posture management.

Cloud Security Meets the AI Workload

Modern enterprise applications are assembled from containers, serverless functions, Kubernetes clusters, application programming interfaces, identities, databases and software pipelines. AI introduces another layer containing models, agents, machine identities, data connectors and automated actions. A security weakness in one component may appear minor until it is combined with excessive permissions or exposed information elsewhere.

Microsoft's position is that organizations need a shared control plane capable of correlating these signals. Defender for Cloud brings together posture assessment, workload protection, attack-path analysis, runtime intelligence and cloud detection and response. The platform is also being extended to examine the configuration and exposure of AI systems.

This reflects an important change in security operations. Teams no longer need another console producing thousands of isolated findings. They need evidence explaining which weaknesses are reachable, whether they are being exploited and what remediation will break the most dangerous attack path.

Questions Enterprises Should Ask

  • Does the platform provide consistent coverage across every cloud provider in use?
  • Can it connect identity permissions with workload and data exposure?
  • Does runtime evidence improve prioritization or merely generate more alerts?
  • Can findings be assigned directly to application owners and development teams?
  • Are AI agents, models and machine identities included in the same governance framework?

In my view, CNAPP consolidation can reduce operational friction, but it also introduces platform concentration. Organizations should avoid assuming that one vendor will provide equal depth across every cloud, workload and development environment. A structured pilot using real applications, red-team scenarios and measurable remediation workflows is more valuable than relying exclusively on an analyst ranking.

I believe the strongest CNAPP strategy will combine broad platform visibility with specialist controls where the business faces unusual risks. The objective is not to eliminate every security product. It is to build a coherent risk model that follows an application from source code to cloud deployment and, increasingly, through the decisions made by its AI agents.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path