Cybersecurity

OX Security Unveils CNAPP Platform Paired With AI Agent Runtime Defense

mm
Add Unite.AI to your preferred sources on Google

OX Security on September 16, 2026 launched OX Cloud, a cloud security product built for environments in which AI agents access data, call tools and take actions autonomously.

The product pairs the coverage of a conventional Cloud-Native Application Protection Platform (CNAPP) with capabilities aimed at live AI activity. According to the company, its AI-native features, AI Detection and Response (AIDR) and Agentic Attack Surface Management, give security teams real-time visibility into AI agents, models and MCP servers: what they can reach, what they are doing and when they act outside intended boundaries. The CNAPP layer includes Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), Data Security Posture Management (DSPM), runtime vulnerability detection, cloud inventory and graph-based attack path analysis.

In an announcement post, authors Jake O’Donnell and Sagiv Peer describe OX Cloud as the runtime pillar of the OX AINAPP, the company’s AI Native Application Protection Platform. The authors write that the product is intended to confirm that upstream governance holds, rather than only identifying exploitable paths after they already exist.

The Risk Framing Behind OX Cloud

The company frames the launch around a shift in what cloud environments run. AI agents increasingly operate in production with identities and permissions, access sensitive data and infrastructure, call tools and take actions autonomously, a combination the company characterizes as a new class of active, dynamic risk that traditional cloud security was not built to address. Traditional tooling covers misconfigurations, vulnerabilities, exposed assets and excessive permissions, but, the company argues, knowing what exists and how it is configured does not show what an AI agent is actually doing inside an environment. The launch release gives examples of that gap: an agent calling a tool it should not, a model accessing data it should not touch, and an MCP server operating outside its intended scope.

The announcement post makes a related argument about conventional CNAPPs: they inventory AI assets, the authors write, but do not connect agent runtime behavior to reachability or to the prompt and code that created the agent.

Capabilities and Operating Functions

A capability table in the post lists the product’s components. AIDR detects and governs AI-driven usage, configuration and threats across cloud and runtime environments in real time. Agentic Attack Surface, powered by the OX Agent, uncovers hidden backdoors and reachable exposures through agentic-level inspection, while Runtime Events supports incident response by investigating runtime anomalies with full context and Runtime Vulnerabilities identifies vulnerabilities actively exposed in running workloads. Cloud Graph and Attack Path Mapping visualizes relationships across cloud assets to show exposures, lateral movement and blast radius. The posture components cover continuous detection of misconfigurations and compliance enforcement across cloud accounts (CSPM), Kubernetes security risks and policy compliance (KSPM), discovery, classification and protection of sensitive data (DSPM), and an always-current inventory of every asset across the cloud estate (Cloud Inventory).

The post organizes those components into four functions. Identify uses Cloud Inventory to surface every workload, identity and AI agent actually running in a cloud, including shadow AI and unmanaged non-human identities. Prioritize applies reachability, through Runtime Vulnerabilities and Attack Path Mapping, so that misconfigurations, vulnerable packages and supply-chain exposure that nothing can reach fall away. Investigate opens each alert into graph-based evidence showing who or what acted, what they touched and what else they could have reached. Govern applies AIDR and Agentic Attack Surface capabilities to enforce boundaries on agents calling tools, models accessing data and MCP servers executing, monitored in real time alongside conventional cloud workloads.

The post’s FAQ defines the terms behind those functions. Non-human identities are the service accounts, API keys, AI agents and automated processes that hold access and permissions without a human directly behind each action. Shadow AI refers to models, agents and tools running inside a cloud environment without the knowledge or approval of security or IT, including unauthorized MCP servers and unsanctioned integrations.

Positioning Against Conventional Tools

The company’s comparison table claims that conventional CNAPPs rely on periodic, batch scans of posture and vulnerabilities under generic rules, adding findings without reachability context, and that AI security add-on tools bolt onto existing cloud tooling after deployment and enumerate a single AI asset class. OX Cloud, by the company’s account, instead runs continuous inventory and real-time detection on live infrastructure, ties findings to evidence of what is actually reachable in a given environment, and shares one live evidence model with the rest of the OX platform.

Neatsun Ziv, cofounder and CEO of OX Security, said in the launch release that cloud security was built to understand infrastructure but that AI agents do not just sit in an environment; they act. “Once AI can call tools, access data and take actions autonomously, knowing what exists is no longer enough. Security teams need to know what it’s doing,” Ziv said.

OX Cloud is available to existing and new OX Security customers as of September 16, 2026.

Miles Okada is an AI-generated analyst at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.