What You Missed on the Expo Floor
Key Moves in CSPM at Black Hat USA 2025:
- Netskope introduced an AI-powered copilot for its Aero Trust Network Access solution.
- Wiz launched HoneyBee, an open-source misconfiguration honeypot generator.
- Orca Security demoed AI-driven cloud scanning with instant misconfiguration prioritization.
- Palo Alto Networks unveiled COBRA for multi-cloud breach simulation and posture testing.
- Abnormal AI added Microsoft 365 misconfiguration detection to its posture platform.
Cloud Security Posture Management (CSPM) was a major focus at Black Hat USA 2025, with vendors showcasing how misconfiguration detection is evolving from static scanning to dynamic, AI-driven remediation. The complexity of multi-cloud environments, combined with the rise of agentic AI and ephemeral infrastructure, has made posture management more critical and more challenging than ever.
Our team was on the ground throughout the event—attending keynotes, sitting in on panel discussions, and speaking directly with solution providers and CISOs. The consensus was clear: Misconfigurations are still the root cause of many breaches, and CSPM tools must now deliver speed, context, and automation to keep up.
Here are some key themes from the show that stood out:
Open-Source Innovation
Open-source innovation was a key theme at the show playing a pivotal role in advancing cloud security. Recent contributions reflect a growing emphasis on practical, hands-on resources that support both research and operational readiness.
Wiz introduced HoneyBee, an open-source tool that uses LLMs to generate deliberately misconfigured Dockerfiles and manifests. Designed for honeypots, detection rule testing, and team training, HoneyBee works across all major cloud providers. It’s a practical way to simulate real-world misconfigurations and validate CSPM coverage.
Wiz also presented findings on container escape vulnerabilities in AI platforms, reinforcing the need for posture management that spans cloud, code, and runtime environments.
AI-Driven Prioritization
It was apparent that AI-driven prioritization is reshaping how security teams manage risk, enabling faster, more informed decisions in complex cloud environments. There was a heavy emphasize on precision, scalability, and alignment with business impact.
Orca Security showcased its AI-native platform that scans cloud workloads, configurations, and identities within hours of deployment. The system automatically ranks misconfigurations by exploitability and business impact, helping teams focus on what matters most.
Orca’s executive team emphasized the importance of context-aware posture management, especially in environments where traditional scanning tools generate overwhelming noise. Their platform integrates with compliance frameworks and threat intelligence to surface high-risk issues in real time.
Breach Simulation Meets Posture Testing
Breach simulation and posture testing almost seemed to converge, offering a more realistic yet unified view of cloud security readiness across infrastructure layers.
Palo Alto Networks launched COBRA, an open-source tool for simulating attacks in multi-cloud environments. COBRA tests external and insider threats, lateral movement, and data exfiltration, providing a comprehensive view of posture weaknesses.
The tool complements Prisma Cloud by enabling red team-style assessments of misconfiguration exposure. Palo Alto’s sessions also highlighted CLARA, a new AI engine for cloud risk assessment, and emphasized the need for unified visibility across code, cloud, and SOC workflows.
Microsoft 365 Misconfigurations
Microsoft 365 misconfigurations emerged as a high-impact risk vector, often overlooked in traditional security assessments.
Abnormal AI announced a major expansion of its Security Posture Management platform to include misconfiguration detection for Microsoft 365. The module scans tenants, users, and third-party apps for risky settings like legacy authentication and overly permissive OAuth scopes.
CEO Evan Reiser explained that attackers are increasingly exploiting configuration gaps to bypass phishing defenses. Abnormal’s deep integration with Microsoft APIs allows it to surface and prioritize these risks using real-time telemetry from over 3,200 customer environments.
What We Heard in the Hallways
“Misconfiguration detection has to be fast, contextual, and actionable. Anything less is noise.”
—Tom Orbach, Security Researcher, Wiz
“We’re seeing posture management shift from dashboards to decisions. That’s the future.”
—Isaiah Walker, Product Marketing Lead, Orca Security
Why It Matters
Misconfiguration detection is a frontline defense. The innovations at Black Hat USA 2025 reflect a shift toward CSPM tools that are proactive, intelligent, and integrated. Whether it’s through honeypots, breach simulations, or AI-native prioritization, the goal is the same: Reduce risk before it becomes an incident.
For BDMs and TDMs, the takeaway is clear: Posture management must evolve with the cloud. Static scans and siloed dashboards won’t cut it. The future of CSPM is real-time, risk-aware, and built for scale.
If your CSPM isn’t helping you make faster, smarter decisions—it may be time to move on. Check out our list of recommended CSPM providers.