Jul 28, 2026
Enterprise

Skyhawk AWS Continuum integration ranks cloud flaws by exploitability

Skyhawk’s AI Red Team now ingests AWS Continuum findings to show which cloud vulnerabilities sit on usable attack paths.

Colin Brandt

By Colin Brandt · Enterprise Reporter

· 3 min read

Skyhawk AWS Continuum integration ranks cloud flaws by exploitability
Photo: SiliconANGLE

Skyhawk Security has integrated AWS Continuum vulnerability findings into its AI Red Team product, using simulated attacks to rank cloud flaws by whether they can be exploited in a broader breach. The Skyhawk AWS Continuum integration matters for security teams drowning in scanner output: it is aimed at separating reachable attack paths from long vulnerability lists. Pricing, customer adoption and any revenue impact were not disclosed.

The cloud detection and response company said the integration arrives ahead of Black Hat USA 2026 in Las Vegas. Skyhawk’s product takes application-layer issues surfaced by AWS Continuum and tests whether those findings can be turned into access to sensitive data or other critical assets in a customer’s cloud environment.

What is AWS Continuum?

AWS Continuum is an Amazon Web Services service launched in June to handle vulnerability workflows across discovery, prioritization, validation and remediation. AWS has described it as model-agnostic, using whichever frontier model performs best for a specific task, and AWS Security Agent, its code review, threat modeling and penetration testing tool for agentic development, is now part of the service.

Skyhawk’s pitch is that finding more flaws does not automatically improve security if teams cannot tell which ones create viable attack paths. The company said its AI Red Team continuously runs against a digital twin of a customer’s live cloud environment, rather than against production systems directly. Starting from a flagged issue, the system evaluates cloud configuration, identities and permissions, network paths and the defenses already in place.

The output, according to Skyhawk, is evidence of whether a vulnerability is positioned on a path an attacker could use. That is a narrower claim than generic AI-assisted prioritization, and it reflects where cloud security vendors are trying to move the category: away from static severity scoring and toward proof that a chain of access can actually be executed.

Skyhawk Chief Executive Chen Burshan said vulnerability volume has become the problem, with advanced models finding more issues than security teams can remediate and exploit timelines shrinking. He argued that enterprises should prioritize fixes according to whether a flaw can be weaponized, rather than trying to repair every finding at the same speed.

The company pointed to a June disclosure as an example of the kind of risk it wants to surface. Skyhawk said its AI Red Team took control of a financial services company’s production AWS organization within seconds from a low-privilege starting point. According to the company, the environment had no misconfigurations or excessive permissions, used a cloud-native application protection platform and showed green status in dashboards. The attack, Skyhawk said, chained legitimate identity and access management permissions, while static attack graph analysis had not shown a takeover route.

The timing lines up with broader pressure on cloud security programs. CrowdStrike’s 2026 Global Threat Report found that cloud-conscious intrusions increased 37%, while cloud targeting by state-linked actors rose 266%. Those figures help explain why vendors are emphasizing exploitability and identity paths rather than treating vulnerability management as a code-only problem.

The AWS Continuum integration also extends Skyhawk’s existing work with AWS security data. Skyhawk already analyzes telemetry from Amazon GuardDuty, Amazon Inspector and Amazon Macie, which the company says gives it more context than findings from AWS Security Hub alone. Skyhawk was spun out in 2022 from the cloud native protection business of Israeli cybersecurity and application delivery vendor Radware.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →