惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Latest news
Latest news
T
Troy Hunt's Blog
V
Vulnerabilities – Threatpost
L
LINUX DO - 热门话题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
V
V2EX
博客园 - 司徒正美
B
Blog RSS Feed
AWS News Blog
AWS News Blog
MyScale Blog
MyScale Blog
Scott Helme
Scott Helme
Cisco Talos Blog
Cisco Talos Blog
Last Week in AI
Last Week in AI
NISL@THU
NISL@THU
博客园 - Franky
P
Proofpoint News Feed
博客园_首页
C
CERT Recently Published Vulnerability Notes
雷峰网
雷峰网
S
Schneier on Security
P
Proofpoint News Feed
Hugging Face - Blog
Hugging Face - Blog
G
GRAHAM CLULEY
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
WordPress大学
WordPress大学
The Hacker News
The Hacker News
T
Threatpost
阮一峰的网络日志
阮一峰的网络日志
A
Arctic Wolf
Microsoft Azure Blog
Microsoft Azure Blog
T
The Exploit Database - CXSecurity.com
Engineering at Meta
Engineering at Meta
罗磊的独立博客
T
The Blog of Author Tim Ferriss
D
Darknet – Hacking Tools, Hacker News & Cyber Security
I
Intezer
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
K
Kaspersky official blog
SecWiki News
SecWiki News
云风的 BLOG
云风的 BLOG
美团技术团队
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Security Latest
Security Latest
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog
S
Security Affairs

Blog | Orca Security

Langflow RCE Actively Exploited to Deploy Cryptominers on AI Infrastructure Orca MCP: When Text Stops Scaling Kubernetes Compliance Tools: Automating CIS Benchmarks Risk-Based Vulnerability Management for the Cloud: A 2026 Guide Private Cloud Security: Top Risks and Best Practices (2026) What Is Generative AI in Cybersecurity? Best Vulnerability Management Tools and Software in 2026 2026 State of Application Security Report Recap: What the Data Says and What Security Teams Should Do About It AI Security for Sensitive Data: Best Practices and Guidelines Best AI Code Security Solutions 2026: How to Secure AI-Generated Code From Platform to Program: How to Ensure Your Cloud Security Solution Delivers Best AI Cybersecurity Providers 2026: A Buyer's Guide to AI-Powered Security Platforms Join Orca Security at Black Hat USA 2026 CNAPP Tools That Reduce Security Tool Sprawl: CNAPP vs. Dedicated Solutions What Is Container Runtime Security? A Practical Guide 2026 What Is Application Security Testing? Tools and Types What Is Managed Cloud Security? A Practical Guide What Is SaaS Security Posture Management? SSPM Guide Top 10 Cloud Security Standards for Compliance What is the MIT License? Compliance and Comparisons AI Agents vs. Agentless Security vs. Agent-based Security 144 Mastra npm Packages Compromised via Supply Chain Attack The Complete Guide to LLM Security: Risks, Best Practices, and Solutions Cloud Security LIVE 2026: Top 10 Takeaways Practitioners Can Use Now Cloud Security LIVE 2026: Top 10 Takeaways CISOs Can Use Now (and What to Do Next) How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code What to Look for in Container Security Tools Cloud Application Security Best Practices for DevSecOps Cloud Security Tools: 10 Types Explained for Teams What Is NIST CSF? Framework 2.0 Explained 7 Open Source Incident Response Tools by Category Critical Langflow Path Traversal Flaw Exploited for Unauthenticated RCE Critical PhpSpreadsheet RCE Patch Bypass Puts Millions at Risk Critical Splunk Enterprise Vulnerabilities Allow Unauthenticated File Operations and Remote Code Execution 16 Best Open Source Application Security Tools 2026 What Is Containerization? Security and Best Practices 8 Container Security Best Practices for 2026 Close the Cloud Identity Gap with Orca and AWS IAM Access Analyzer The 5-Step Context-Aware Cloud Vulnerability Prioritization Framework Critical Jupyter Enterprise Gateway Vulnerabilities Enable Full Kubernetes Cluster Takeover AI Security Best Practices for Regulated Industries Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks SAST vs SCA: Key Differences for AppSec Teams What Is Cloud Security Architecture? Principles, Layers, and Frameworks What Is ASPM? A Guide to Application Security Posture Management What Is SaaS Security? A Practical Guide 2026 What Is a Man-in-the-Middle Attack? A Cloud Security Guide What Is Open Policy Agent? Best Practices and Use Cases 11 Best Open-Source DevSecOps Tools for 2026 How to Secure AI Workloads in Multi-Cloud Environments: A Complete Framework Critical WordPress Plugin Vulnerability Allows Unauthenticated Admin Takeover on 150K Sites What Is Kubernetes as a Service? KaaS Explained Critical Netlogon RCE Flaw Actively Exploited Against Windows Domain Controllers Your FedRAMP Continuous Monitoring Strategy Has a Gap. We Built Something to Fix It. How to Simplify Multi-Cloud Compliance Reporting: The 2026 Checklist Red Hat npm Packages Compromised in Supply-Chain Attack Spreading Credential-Stealing Worm Critical RCE in LiquidJS Lets Attackers Execute Arbitrary Commands on Unpatched Hosts Securing Shadow AI: How to Detect Unapproved LLMs in Your Cloud Data Security Posture Management (DSPM) for AI Gitea Container Registry Exposes Private Images to Unauthenticated Attackers Critical Unauthenticated RCE in Kopia Backup via SSH ProxyCommand Injection Best Palo Alto Networks Cortex (Prisma Cloud) Alternatives in 2026 7 Enterprise AI Security Risks to Manage Critical Pre-Auth RCE in ChromaDB Threatens AI Infrastructure Critical Coder Signature Bypass Exposes Developer Keys and Tokens New “PoolSlip” NGINX Exploit Revives Unpatched Remote Code Execution Risk Critical Drupal SQL Injection Exposes PostgreSQL-Backed Sites to Remote Code Execution AI Security Tools: How to Evaluate Them Across Every ML Attack Phase Massive npm Supply Chain Attack Compromises AntV Ecosystem, Steals CI/CD Secrets at Scale NIST AI Risk Management Framework (AI RMF) Explained: What It Is and How Organizations Use It The AI Data You Forgot to Lock: How Exposed Vector Databases Put Organizations at Risk GenAI Risks in Cloud Environments: What Security Teams Are Actually Missing in 2026 What Is Multi-Cloud Security? What Is Cloud Detection and Response (CDR)? Linux kernel vulnerability enables local theft of SSH host keys and /etc/shadow 18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated DoS and Potential RCE TanStack and 160+ npm/PyPI Packages Compromised in Supply Chain Worm Attack Dirty Frag: Linux Kernel Vulnerability Chain Enables Local Privilege Escalation to Root Critical Apache HTTP Server HTTP/2 Vulnerability Could Enable Remote Code Execution Skill Issues: How We Discovered Supply Chain Attack Vectors in an AI Agent Skills Marketplace What Is an Incident Response Plan? What Is Cloud Data Security? Risks, Challenges, and 12 Best Practices Remote Code Execution in GitHub Enterprise Server via Git Push Injection (CVE-2026-3854) Linux Kernel Bug (Copy.Fail) Enables Local Privilege Escalation to Root (CVE-2026-31431) Xinference PyPI package compromise leads to full environment takeover What is Application Security? When AI Accelerates the Offense, Coverage Gaps Become Catastrophic Orca Security Recognized in the 2026 TAG Enterprise AI Security Handbook Navigating Cloud Security in 2026: Join Cloud Security LIVE Anthropic’s Project Glasswing Is a Positive Step Toward Cleaner, Safer Production Kyverno SSRF: Breaking Kubernetes Namespace Isolation (CVE-2026-4789) Streamline Compliance Reporting with Orca and Drata’s Integrated Vulnerability Management CVE-2026-23226: How a Missing Lock in ksmbd’s Channel List Exposes Your Linux SMB3 Server 2026 State of AppSec: When Development Velocity Outpaces Security AI Is Entering Your Infrastructure. Now what? Orca Security Featured in SACR’s 2026 Unified Agentic Defense Platforms Report Supply Chain Attack on Axios Delivers Cross-Platform RAT via Compromised npm Account Credential‑Stealing Malware in LiteLLM Supply Chain Attack Mission Accomplished: Orchestrate Your Remediation Strategy With Orca Missions The Orca Approach to Runtime AI Security
Announcing Cloud Security Agent Skills for Orca’s MCP Server
Ashleigh Lee · 2026-05-13 · via Blog | Orca Security

Table of contents

  • Orca’s Unified Data Model Drives Reliable AI Workflows
  • What Connecting the Orca MCP Server Does
  • Agent Skills to Operationalize Orca Data
  • About the Orca Cloud Security Platform

The gap between security data and security decisions has never been smaller.

Cloud security teams are drowning in the right data. They have asset inventories, vulnerability feeds, compliance scores, CloudTrail logs, attack paths. The problem isn’t data availability. It’s the distance between raw findings and the analysis a practitioner actually needs to act.

That gap is what today’s announcement is designed to close.

Orca Security’s AI Skills Hub is now live and compatible with Claude, Codex, and Cursor. These cloud security skills let security engineers, developers, SOC analysts, and security leaders query, investigate, and operationalize Orca data. Customers never have to learn another query language, write a single line of code, or leave their existing tools. Just use natural language to understand what matters most and drive action.

Orca’s Unified Data Model Drives Reliable AI Workflows

When a model doesn’t have access to ground truth, it fills the gaps with inference, leading to AI hallucinations. That’s reasonable behavior in a general-purpose assistant. It’s an unacceptable one when the output is a triage verdict, a remediation recommendation, or an incident investigation.

Most security AI integrations expose a slice of the data: alerts from one source, asset metadata from another, compliance scores pulled separately. The model reasons across disconnected fragments and the seams show: contradictory conclusions, missing context, recommendations that don’t account for the actual environment.

Orca’s Unified Data Model was built to eliminate those seams. Every asset, alert, identity, data finding, attack path, and CDR event is ingested into a single continuously updated graph that is correlated, normalized, and queryable as a coherent whole. A vulnerability on an EC2 instance is understood in relation to the instance’s network exposure, the IAM role attached to it, the attack paths that pass through it, and the compliance frameworks that govern it. Not as four separate facts in four separate systems, but as one connected picture.

Orca’s structural coherence is what makes AI workflows reliable at scale. When Claude queries Orca through the MCP Server, it’s not assembling a response from 8 different systems with partial signals. It’s reasoning against a complete, authoritative representation of your cloud environment. AI output is only as trustworthy as the data underneath it. Orca’s Unified Data Model is why the output is trustworthy.

What Connecting the Orca MCP Server Does

Connecting Orca with Claude is like giving a doctor your full medical history to diagnose and treat your health concerns. Claude gets direct access to your Orca environment data through Orca’s MCP Server.

Architecture diagram of the Model Context Protocol (MCP) integration connecting an MCP Client to the Orca Platform via an Orca MCP Server.

When you ask a question, Claude queries your actual asset inventory, your open alerts, your compliance frameworks, your CloudTrail logs.

The result is a conversation with AI that actually knows what it’s talking about.

Ask “what’s exposed to the internet right now?” and Claude pulls your live exposure map including internet-facing assets ranked by exploitability, public storage buckets, exposed management interfaces, and outside-in attack paths. 

Ask “who created this misconfiguration?” and Claude traces the resource back through CloudTrail audit logs, IaC source code, and git blame data to identify the exact deployment that introduced the issue and who owns the fix.

Agent Skills to Operationalize Orca Data

If connecting AI to Orca’s MCP Server is like giving the doctor your medical history, agent skills are like specialist consultations. The MCP Server provides context, the skills deliver expertise to know what to look for and how to interpret what they find. The result is AI output you can act on immediately, not a starting point for more investigation.

Skills are purpose-built, role-specific workflows that codify specialized security logic, like the kind of investigation sequence a senior analyst runs, but automated and repeatable. Each skill is triggered by natural language and follows a consistent pattern: gather relevant Orca data, apply expert-level analysis logic, deliver a verdict-first output with drill-down options.

Orca’s AI Skills Hub starts with 11 out-of-the-box skills covering the most common and most time-intensive cloud security workflows:

  • orca-morning-briefing answers “what happened while I was away?” It scans the last 24–72 hours for new critical alerts, escalated findings, compliance drift, CDR anomalies, crown jewel risks, and aging unactioned findings. Then it delivers a scannable dashboard with progressive drill-down by keyword.
  • orca-alert-triage answers “what is this alert and should I care?” It produces verdict-first summaries with confidence scoring, behavioral timelines, blast radius calculations, and Orca-first automated investigation before suggesting any manual steps. Remediation code is written directly to a file in the format you specify— Terraform, CloudFormation, ARM/Bicep, Pulumi, CLI, or step-by-step instructions.
  • orca-impact-analysis answers “if I fix this, what else closes and what breaks?” Before a fix is applied, this skill maps all alerts sharing the same root cause, identifies attack paths that break, calculates compliance score improvements per framework, and surfaces production dependencies that might be disrupted. Teams can use this to make informed fix-or-defer decisions.
  • orca-config-origin answers “who did this, and what introduced the issue?” It traces any alert back through CDR audit logs and Orca CodeOrigins / Shift Left data to identify the specific deployment, the IaC source file and line number, the git commit author, and the full timeline from code commit to alert detection.
  • orca-identity-review answers “is this identity overprivileged, and what’s the blast radius?” It compares effective permissions against 30-day CloudTrail usage, identifies dangerous permissions never exercised, maps lateral movement potential, and generates a least-privilege policy recommendation with a safe deployment checklist.
  • orca-investigate answers “what happened, who did it, and how far did they get?” It runs CDR-powered incident investigation, clustering events into sessions, mapping actions to MITRE ATT&CK techniques, assessing blast radius, extracting IOCs in copy-paste format for SOC tools, and delivering a verdict with confidence scoring.

The remaining skills—orca-asset-profile, orca-compliance-gap, orca-data-exposure, orca-exposure-map, and orca-cloud-cost-optimizer—cover the full range of daily security operations: asset 360 views, compliance gap analysis with phased remediation plans, DSPM-style sensitive data discovery, external attack surface mapping, and cloud cost optimization across compute, storage, and networking.

Skills ship with the logic already written. An analyst doesn’t configure a workflow, define a query schema, or map data fields. They type a question like “triage alert orca-9012345” or “what’s our PCI compliance gap?” and the skill handles everything from data retrieval to output formatting. See an example of how easy it is to ask Claude to provide a daily briefing and then an impact analysis of one of the action items:

The experience is just as easy in Claude Code:

Outputs are designed for immediate use. Triage results include verdicts, confidence scores, and timeline analysis in a format readable in under 30 seconds. Remediation outputs are written to files in the IaC format the team already uses. Compliance gap analyses include projected score improvements per fix, phased over days, weeks, and months.

Skills are also extensible. Orca’s Skills Library is open-source and available at github.com/orcasecurity/orca-skills. Every skill includes its full implementation, natural language trigger patterns, and automated test suites. Teams can fork, modify, and extend skills to fit their specific workflows. Pull requests are welcome. 

This isn’t a locked capability behind an enterprise tier. It’s a foundation the security community can build on.

The gap between security data and security decisions closes today.

About the Orca Cloud Security Platform

The Orca Platform delivers a unified cloud security experience that helps organizations identify, prioritize, and remediate risk across their cloud environments, applications, and AI. To get started with Orca’s MCP Server, check out our documentation.

Interested in seeing how we help you command your cloud? Schedule a personalized 1:1 demo.