#AI tools and autonomous agents are redefining who can build software.
@orcasec CEO Gil Geron breaks down why security teams must rethink visibility and permissions as shadow #IT evolves.
Read the full article 👇️
securitytoday.com/articles/2…
Every team is building with AI now. How does security keep up?
We're hosting The Builder Exchange on Nov 4 with security leaders.
orca.security/builder-exchan…
Our Head of Distribution built a partner portal with AI in one weekend.
Our CEO wanted to launch it. Then he asked: had security seen it yet?
linkedin.com/safety/go/?url=…
Who's building software at your company that you don't know about?
Our CEO Gil talked to Let's Data Science about it. AI isn't just helping attackers move faster, it's letting anyone build apps and automations of their own.
Read here: letsdatascience.com/news/orc…
We're heading to the Gartner Security & Risk Management Summit, 22–24 September at ExCeL London. Come find us at booth 418!
Book a demo ahead of time or just stop by: try.orca.security/gartner_sr…
Pre-built agent, or build your own?
Orca ships both. Threat Investigator for the alerts you see every day. The MCP Server for the ones only your team would know to look for.
Same data, different job.
orca.security/resources/blog…
Model cards don't stop sandbox escapes.
Federal AI strategies this spring covered paperwork. Four months later, an AI agent chained a sandbox escape into a production breach.
3 gaps between AI governance and AI security 👇
orca.security/resources/blog…
A CMDB nobody trusts isn't an inventory. It's a guess.
Orca keeps ServiceNow CMDB current automatically: assets, risk scores, and cleanup, all synced from your cloud in real time.
orca.security/resources/prod…
New: the Orca Browser Extension is live on the Chrome Web Store.
Orca's findings, right inside the AWS console, on the exact resource you're viewing. No new tab. No context switch.
How it works: orca.security/resources/blog…
Most security programs still measure success by counting blocked attacks.
What matters is how fast you catch an attacker once they're in. Zero breach isn't the goal. Zero impact is.
Full recap from Cloud Security LIVE 2026: orca.security/resources/webi…
The ECB just handed banks a deadline: AI cyber action plan due 31 October.
The catch: every commitment in that plan depends on an accurate asset inventory. Most banks don't have one.
Here's what the letter actually requires → orca.security/resources/blog…
Our Claude Connector is live on Anthropic's Claude directory.
Now anyone can connect Orca's MCP Server directly to Claude and get deep, accurate context on their cloud and AI risk, right where they're already working.
See how it works: orca.security/resources/blog…
Least privilege isn't enough anymore. You also need least autonomy.
At Cloud Security LIVE 2026, our CEO talked agentic AI risk with the CSA and Zscaler.
One idea that stuck: a restricted agent can just ask a more permissive one to do the job for it.
orca.security/resources/blog…
AI is in production. Security hasn't caught up.
81% of orgs with AI packages have a known vulnerability. Over half run AI agents with zero guardrails.
We dug through telemetry from 1,200+ production orgs to find out why.
🔗 orca.security/lp/2026-state-…
An alert firing is easy. Chasing it through five tools until it's actually resolved is not.
Orca Workflows chains actions, approvals, delays, and agent handoffs into one automated playbook, where your cloud context lives.
No tool-hopping required.
orca.security/resources/blog…
Zoom just patched a zero-click RCE bug.
One malicious drawing during screen share = full code execution on every participant's device. No clicks needed.
Update to Zoom 7.1.5+ now. Details 👇
orca.security/resources/rese…
Black Hat 2026's big theme: AI is everywhere, but the real question is whether it acts safely.
Agent governance, attack paths over CVE counts, AppSec tools racing to keep up with AI-generated code, that's what we kept hearing.
More on what we saw here:orca.security/resources/blog…
No one should have permanently assigned access to your cloud.
Our JIT access integration with AWS IAM Identity Center scopes permissions, sets a time window, and auto-revokes when it closes. Nothing to remember to clean up.
Details here: aws.amazon.com/blogs/apn/orc…
Findings without context are just more alerts.
That's why Orca's Core Agents run in pods: Red attacks, Blue investigates, Green resolves. Same Unified Data Model throughout.
Take a look inside the pods: orca.security/resources/blog…