Frost & Sullivan has recognized Microsoft as a visionary leader in its 2026 Cloud Workload Protection Platforms report. The analysis highlights Microsoft's comprehensive approach to securing cloud-native architectures, emphasizing the need for runtime security that integrates code, cloud resources, identities, and operational data. Microsoft's Defender for Cloud platform was specifically noted for its broad coverage and integration within the company's security ecosystem.

Frost & Sullivan has identified Microsoft as a visionary leader in its 2026 Cloud Workload Protection Platforms (CWPP) report. The analysis specifically acknowledges Microsoft's comprehensive strategy for securing cloud-native architectures, with a particular focus on the necessity of runtime security that effectively integrates code, cloud resources, identities, and operational data.
The report underscores the critical role of runtime security in modern cloud environments. This aspect of security focuses on protecting applications and workloads as they execute, rather than solely during development or deployment phases. It involves continuous monitoring and analysis of behavior, resource access, and data flow to detect and prevent threats that might bypass static security controls.
Microsoft's Defender for Cloud platform was highlighted in the report for its extensive coverage and deep integration within the broader Microsoft security ecosystem. Defender for Cloud provides a unified platform for security posture management and threat protection across hybrid and multi-cloud environments. It offers capabilities such as vulnerability management, just-in-time VM access, adaptive application controls, and file integrity monitoring.
Products in the CWPP category typically aim to provide comprehensive security for diverse cloud workloads, including virtual machines, containers, and serverless functions. These platforms commonly offer features like host-based intrusion prevention, vulnerability scanning, network segmentation, and behavioral analytics to protect against a wide range of threats. The integration of various security telemetry sources, such as identity and access management data, is a common characteristic of advanced CWPP solutions.
The emphasis on integrating code, cloud resources, identities, and operational data points to a holistic security approach. This integration allows for a more contextual understanding of potential threats, as anomalies in one area can be correlated with events in others. For instance, unusual code execution patterns combined with suspicious identity activity could signal a sophisticated attack.
Mitigation strategies for cloud workload protection generally involve adopting a layered security approach. This includes implementing strong identity and access management, enforcing least privilege principles, regularly patching and updating systems, and deploying robust CWPP solutions. Continuous monitoring and automated response capabilities are also crucial for maintaining a strong security posture in dynamic cloud environments.
This recognition by Frost & Sullivan places Microsoft among the leading vendors in the CWPP market, reflecting the ongoing industry trend towards more integrated and intelligent cloud security solutions. As organizations increasingly adopt cloud-native architectures, the demand for platforms that can provide comprehensive, runtime-aware protection across the entire cloud stack continues to grow.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed