As Frontier AI accelerates software development and enables attackers to discover vulnerabilities, chain exploits, and compromise environments faster than ever, traditional cloud security approaches can no longer keep pace. Fragmented tools leave critical blind spots between code, cloud, identities, and data, making it harder for security teams to identify and stop the risks that matter most.
Today, with the launch of Cortex Cloud 2.2 we’re delivering major enhancements across application security, cloud posture, and runtime protection. This release helps organizations strengthen software supply chain security, eliminate cross-domain blind spots, uncover complex attack paths, and accelerate remediation—all from the unified Cortex platform. Here's a look at some of the key innovations and what they mean for your organization.
Accelerate Response to Emerging Supply Chain Attacks
Responding to supply chain attacks remains a slow, manual process. Security teams must first understand what was affected, then search their environments to determine whether the impacted tools, packages, or dependencies are in use.
The new Supply Chain Attack Threat Center in Cortex Cloud streamlines this process. By providing organizations with the latest information on software supply chain attacks—including CVEs, compromised tools, and malicious packages—and automatically analyzes their environment for affected assets, Cortex Cloud enables teams to quickly determine exposures and accelerate responses.

New Code to Cloud Tracing Coverage Dashboard
Every CNAPP today claims to connect code and cloud. Over time tracing and visibility have improved, but until today gaps still exist.

Cortex Cloud 2.2 introduces Code-to-Cloud Coverage Tracing, enabling organizations to bridge critical gaps across their code-to-cloud environment. By tracing assets end-to-end, the platform automatically identifies missing connections and helps teams close them.
Eliminating these blind spots provides the context needed to improve risk prioritization, accelerate remediation, and strengthen collaboration across AppSec, CloudSec and SOC teams.
New Graph-Powered Attack Path Detections
Securing the modern cloud requires seeing how isolated risks connect across identities, data, workloads, and infrastructure. Traditional cloud security tools often see simple, linear attack paths but often miss more sophisticated risks. Cortex Cloud 2.2 introduces a brand new capability that uses graph-powered intelligence with context to reveal hidden hazards before they can be exploited.

Graph-Powered Attack Path Detection combines precise user access rules, AI pathfinding, and real-world Unit 42 threat intelligence to automatically connect isolated cloud risks. Instead of looking at isolated paths, it calculates the exact multi-hop pathways an attacker could take to reach your sensitive assets. This helps you prioritize complex posture risks with pinpoint accuracy. By highlighting these interconnected chains, you can easily shut down an entire threat vector with a single targeted fix long before an exploit ever happens.
Catch Zero Day Threats Before Deployment with Agentless Cloud Sandboxing
Securing the modern cloud requires catching hidden malware before it ever reaches production. Traditional security tools often rely on heavy host agents, adding operational friction, maintenance complexity, and unwanted performance overhead. That is why Cortex Cloud introduces agentless malware sandboxing powered by Advanced WildFire. This brings active detonation and conviction of unknown files directly to your container registries. Now you can expose zero day threats and eliminate registry blind spots long before they can be exploited, all without the friction of traditional agents.

More Innovations Across Cortex Cloud 2.2
Beyond the major innovations highlighted above, Cortex Cloud 2.2 introduces numerous enhancements across the platform to help organizations strengthen prevention, improve visibility, and accelerate response.
Application Security
- Expanded AppSec Ecosystem: Seamlessly ingest Checkmarx SAST and SCA findings into Cortex Cloud to centralize visibility, improve prioritization, and strengthen prevention without disrupting existing development processes.
- New Artifact Trust Scoring: Easily determine whether a code artifact is secure by evaluating the security posture of the tools, identities, and pipelines that produced them.
Cloud Posture Security
- Extended Threat Intelligence (XTI): Bring adversary intelligence directly into analyst workflows with curated, up-to-date threat data and AI-driven behavioral analysis. Powered by Unit 42, the Threat Intelligence Library delivers a unified catalog of threat actors, malware, and TTPs to accelerate threat hunting and investigations. Additional license required.
- Expanded DSPM Coverage: Extend sensitive data discovery, classification, exposure analysis, and governance across SaaS and AI environments, including Google Drive, Microsoft 365, Teams, Salesforce, and Claude.
- AI Dataset Security for AWS S3 Vectors: Discover and assess AI datasets in AWS Bedrock environments for risky configurations, exposure paths, and sensitive data.
- File Topic Classification: Accelerate sensitive data review with AI-powered document classification that categorizes files by business topic and risk context.
- Cloud Service Provider API Ingestion: Gain faster visibility into newly released cloud services and assets with expanded API coverage, increasing support by approximately 10x more cloud provider APIs each month.
- Compliance-Based Rule Customization: Reduce alert fatigue by tailoring compliance policies to your organization's risk profile with customizable rule severities and flexible policy controls.
Cloud Runtime Security
- Expanded Container as a Service (CaaS) Support: Protect CaaS workloads from unauthorized changes and attacks with real-time drift detection and enhanced image scanning across AWS, Azure, and GCP.
- Kubernetes Graph: Visualize Kubernetes relationships to prioritize risks and accelerate incident investigation and remediation.
- Base Image Upgrade Recommendations: Identify the optimal upgrade path for base images directly within existing workflows to reduce risk with minimal disruption.
Accelerate Innovation and Secure Your Cloud.
Modern cloud security shouldn't force organizations to choose between developer velocity and comprehensive protection. Cortex Cloud 2.2 helps security teams identify, prioritize, and remediate the critical risks with unified code-to-cloud visibility, graph-powered context, agentless malware detection, and software supply chain security.
Ready to see how Cortex Cloud 2.2 can help you uncover complex risks and accelerate remediation. Request a demo today.