Fourteen announcements from January to September 2026 from the vendors we compare and the open-source projects around them, newest first. The largest were Google completing its acquisition of Wiz in March and Upwind's $250 million Series B in January. Announcements do not change scores until the capability is documented as available.
SentinelOne
SentinelOne extends Wayfinder Threat Hunting to AWS, Azure and Google Cloud
The managed hunting service now covers cloud control-plane activity such as IAM privilege escalation, suspicious IAM policy changes and S3 bucket reconnaissance. It is available to existing Wayfinder Threat Hunting customers through Singularity Marketplace plugins.
The CNCF runtime detection project that Sysdig created added raw byte matching in rule conditions, reload status endpoints, driver 11.0.0 and rules that flag containers accessing GPU devices.
Orca launches a global partner program and a Partner Success Platform
Orca announced the Partner POD Program, which rewards partners across the customer lifecycle including net retention, and an AI-based Partner Success Platform available globally in six languages at launch.
Wiz says Wiz for Gov is now GovRAMP High authorized, validated against NIST SP 800-53r5 controls, which makes it easier for US state and public sector organizations to adopt.
Palo Alto Networks acquired Console, an AI-native platform for resolving alerts, issues and requests, and says the deal will deepen agentic capabilities in Cortex. Terms were not disclosed.
Wiz Penetration Test Findings reaches general availability
The feature brings findings from bug bounties, third-party audits, red team exercises and AI pen-test tools into Wiz and correlates them with the Wiz Security Graph.
Foundational CSPM becomes opt-in for new Azure subscriptions
From 27 October 2026, the free Foundational CSPM tier of Defender for Cloud will no longer be turned on by default for new Azure subscriptions. It remains free, and existing subscriptions and AWS and GCP connectors are not affected.
Orca announces AI AppGen Security and AI Code Security Auditor
Unveiled ahead of Black Hat USA 2026, AI AppGen Security finds apps built on AI app builders outside standard pipelines, and AI Code Security Auditor applies AI-driven static analysis to code in existing pipelines. Orca expects general availability later in 2026.
Aqua adds agentic response and runtime risk dashboards
Aqua announced Aqua Compass, an MCP server that lets AI agents investigate, contain and remediate runtime incidents with human oversight, and dashboards that express runtime risk as monetary exposure.
CrowdStrike adds adversary-informed risk prioritization to Falcon Cloud Security
Announced at RSA 2026: a Cloud Risk Engine that maps cloud risks to adversary tradecraft, plus Application Explorer, Timeline Explorer and unified real-time cloud detection and response.
We include product launches, acquisitions, funding, leadership changes and certifications that a buyer comparing these platforms would want to know about. Every item links to the vendor's or project's own page. Vendor performance figures in press releases are left out.