* [Blog](https://www.paloaltonetworks.com/blog) * [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/) * [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/) * Introducing Cortex Cloud ... # Introducing Cortex Cloud 2.2: Defend Against Frontier AI Threats [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fcortex-cloud-2-2%2F) [](https://twitter.com/share?text=Introducing+Cortex+Cloud+2.2%3A+Defend+Against+Frontier+AI+Threats&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fcortex-cloud-2-2%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fcortex-cloud-2-2%2F&title=Introducing+Cortex+Cloud+2.2%3A+Defend+Against+Frontier+AI+Threats&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/cloud-security/cortex-cloud-2-2/&ts=markdown) \[\](mailto:?subject=Introducing Cortex Cloud 2.2: Defend Against Frontier AI Threats) Link copied By [Cody Queen](https://www.paloaltonetworks.com/blog/author/cody-queen/?ts=markdown "Posts by Cody Queen") Jul 28, 2026 5 minutes [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown) [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown) [Cloud Detection and Response](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-detection-and-response/?ts=markdown) [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown) [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown) [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown) [CDR](https://www.paloaltonetworks.com/blog/tag/cdr/?ts=markdown) [Cloud](https://www.paloaltonetworks.com/blog/tag/cloud/?ts=markdown) [Runtime](https://www.paloaltonetworks.com/blog/tag/runtime/?ts=markdown) As Frontier AI accelerates software development and enables attackers to discover vulnerabilities, chain exploits, and compromise environments faster than ever, traditional cloud security approaches can no longer keep pace. Fragmented tools leave critical blind spots between code, cloud, identities, and data, making it harder for security teams to identify and stop the risks that matter most. Today, with the launch of Cortex Cloud 2.2 we're delivering major enhancements across application security, cloud posture, and runtime protection. This release helps organizations strengthen software supply chain security, eliminate cross-domain blind spots, uncover complex attack paths, and accelerate remediation---all from the unified Cortex platform. Here's a look at some of the key innovations and what they mean for your organization. ## Accelerate Response to Emerging Supply Chain Attacks Responding to supply chain attacks remains a slow, manual process. Security teams must first understand what was affected, then search their environments to determine whether the impacted tools, packages, or dependencies are in use. The new Supply Chain Attack Threat Center in Cortex Cloud streamlines this process. By providing organizations with the latest information on software supply chain attacks---including CVEs, compromised tools, and malicious packages---and automatically analyzes their environment for affected assets, Cortex Cloud enables teams to quickly determine exposures and accelerate responses. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-363326-1.png) Image 1: Cortex Cloud's New Supply Chain Attack Threat Center ## New Code to Cloud Tracing Coverage Dashboard Every CNAPP today claims to connect code and cloud. Over time tracing and visibility have improved, but until today gaps still exist. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-363326-2.png) Image 2: Code to Cloud Tracing Coverage Cortex Cloud 2.2 introduces Code-to-Cloud Coverage Tracing, enabling organizations to bridge critical gaps across their code-to-cloud environment. By tracing assets end-to-end, the platform automatically identifies missing connections and helps teams close them. Eliminating these blind spots provides the context needed to improve risk prioritization, accelerate remediation, and strengthen collaboration across AppSec, CloudSec and SOC teams. ## New Graph-Powered Attack Path Detections Securing the modern cloud requires seeing how isolated risks connect across identities, data, workloads, and infrastructure. Traditional cloud security tools often see simple, linear attack paths but often miss more sophisticated risks. Cortex Cloud 2.2 introduces a brand new capability that uses graph-powered intelligence with context to reveal hidden hazards before they can be exploited. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-363326-3.png) Image 3. Cloud Posture Attack Path Detection Graph-Powered Attack Path Detection combines precise user access rules, AI pathfinding, and real-world Unit 42 threat intelligence to automatically connect isolated cloud risks. Instead of looking at isolated paths, it calculates the exact multi-hop pathways an attacker could take to reach your sensitive assets. This helps you prioritize complex posture risks with pinpoint accuracy. By highlighting these interconnected chains, you can easily shut down an entire threat vector with a single targeted fix long before an exploit ever happens. ## Catch Zero Day Threats Before Deployment with Agentless Cloud Sandboxing Securing the modern cloud requires catching hidden malware before it ever reaches production. Traditional security tools often rely on heavy host agents, adding operational friction, maintenance complexity, and unwanted performance overhead. That is why Cortex Cloud introduces agentless malware sandboxing powered by Advanced WildFire. This brings active detonation and conviction of unknown files directly to your container registries. Now you can expose zero day threats and eliminate registry blind spots long before they can be exploited, all without the friction of traditional agents. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-363326-4.png) Image 5. How Agentless Malware Sandboxing Works in Cortex Cloud ## More Innovations Across Cortex Cloud 2.2 Beyond the major innovations highlighted above, Cortex Cloud 2.2 introduces numerous enhancements across the platform to help organizations strengthen prevention, improve visibility, and accelerate response. #### Application Security * **Expanded AppSec Ecosystem:** Seamlessly ingest Checkmarx SAST and SCA findings into Cortex Cloud to centralize visibility, improve prioritization, and strengthen prevention without disrupting existing development processes. * **New Artifact Trust Scoring:** Easily determine whether a code artifact is secure by evaluating the security posture of the tools, identities, and pipelines that produced them. #### Cloud Posture Security * **Extended Threat Intelligence (XTI):** Bring adversary intelligence directly into analyst workflows with curated, up-to-date threat data and AI-driven behavioral analysis. Powered by Unit 42, the Threat Intelligence Library delivers a unified catalog of threat actors, malware, and TTPs to accelerate threat hunting and investigations. Additional license required. * **Expanded DSPM Coverage:** Extend sensitive data discovery, classification, exposure analysis, and governance across SaaS and AI environments, including Google Drive, Microsoft 365, Teams, Salesforce, and Claude. * **AI Dataset Security for AWS S3 Vectors:** Discover and assess AI datasets in AWS Bedrock environments for risky configurations, exposure paths, and sensitive data. * **File Topic Classification:** Accelerate sensitive data review with AI-powered document classification that categorizes files by business topic and risk context. * **Cloud Service Provider API Ingestion:** Gain faster visibility into newly released cloud services and assets with expanded API coverage, increasing support by approximately 10x more cloud provider APIs each month. * **Compliance-Based Rule Customization:** Reduce alert fatigue by tailoring compliance policies to your organization's risk profile with customizable rule severities and flexible policy controls. #### Cloud Runtime Security * **Expanded Container as a Service (CaaS) Support:** Protect CaaS workloads from unauthorized changes and attacks with real-time drift detection and enhanced image scanning across AWS, Azure, and GCP. * **Kubernetes Graph:** Visualize Kubernetes relationships to prioritize risks and accelerate incident investigation and remediation. * **Base Image Upgrade Recommendations:** Identify the optimal upgrade path for base images directly within existing workflows to reduce risk with minimal disruption. ## Accelerate Innovation and Secure Your Cloud. Modern cloud security shouldn't force organizations to choose between developer velocity and comprehensive protection. Cortex Cloud 2.2 helps security teams identify, prioritize, and remediate the critical risks with unified code-to-cloud visibility, graph-powered context, agentless malware detection, and software supply chain security. To learn more about these new capabilities and see Cortex Cloud 2.2 in action, join us for our Cortex Forward webinar. *** ** * ** *** ## Related Blogs ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Threat Intelligence](https://www.paloaltonetworks.com/blog/category/threat-intelligence-1/?ts=markdown) [#### Where Cloud Security Stands Today and Where AI Breaks It](https://www.paloaltonetworks.com/blog/2025/12/cloud-security-2025-report-insights/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud ASM](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-asm/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown) [#### What's New in Cortex Cloud](https://www.paloaltonetworks.com/blog/cloud-security/attack-surface-dspm-fim/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud ASM](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-asm/?ts=markdown), [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown), [CSPM](https://www.paloaltonetworks.com/blog/cloud-security/category/cspm/?ts=markdown) [#### Cloud Attack Surface Management: See What Other CNAPPs Miss](https://www.paloaltonetworks.com/blog/cloud-security/closing-cloud-gap-attack-surface-management/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/cloud-security/category/announcement/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Prisma Cloud: Darwin Release Introduces Code to Cloud Intelligence](https://www.paloaltonetworks.com/blog/2023/10/announcing-innovations-cnapp-prisma-cloud/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud Network Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-network-security/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Shift Happens, Be Ready With Code-to-Cloud CNAPP](https://www.paloaltonetworks.com/blog/2022/09/code-to-cloud-cnapp/) ### [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [Cloud Runtime Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-runtime-security/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown) [#### Your Riskiest Kubernetes Workload Is Hiding in Plain Sight](https://www.paloaltonetworks.com/blog/cloud-security/your-riskiest-kubernetes-workload-is-hiding-in-plain-sight/) ### Subscribe to Cloud Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language