
Cloud-Native Security’s Next Step: Adding Runtime Context to Scan Results
Scanning is the starting point for identifying vulnerabilities, misconfigurations, and external exposures. However, actual risk depends on whether the affected asset is running, whether an attacker can reach it, and whether it is showing signs of abnormal behavior. WERANA Veluna analyzes the execution context of Kubernetes, containers, and hosts through eBPF, helping teams prioritize the threats that matter most in real operating environments.
Despite the rapid advancement of security tools and detection technologies, security teams continue to face increasing operational pressure. The paradox is clear: the more threats an organization can detect, the harder it becomes to determine which ones require immediate action.
Security teams are often overwhelmed by the sheer volume of vulnerability alerts generated every day. Too much time is spent separating real threats from informational noise, making it difficult to secure the critical window of time needed for immediate response. This is why cloud security must move beyond static scanning alone and adopt runtime context — real-time execution data — as a core standard for modern protection.
The Limits of Static Scanning in Cloud Environments in 2026

Alert Noise, Resource Waste, and the Challenge of Identifying Real Threats
Cloud-native environments in 2026 are highly dynamic. Tens of thousands of containers and serverless functions can be created, updated, and terminated within short periods of time. In this environment, traditional static scanning has clear operational limits.
According to industry analysis, less than 5% of all Common Vulnerabilities and Exposures, or CVEs, are likely to be exploitable in an actual runtime environment. The remaining 95% often represent informational noise: vulnerabilities installed in unused packages, assets isolated from external access, or components that are not actually loaded or executed.
When security teams spend most of their time filtering this noise, they lose the ability to focus on threats that pose immediate operational risk.
Visibility Gaps and the Speed of Automated Attacks
Traditional image scanning monitors artifacts in their static state, such as images stored in registries. However, it often lacks visibility into what happens after deployment: container configuration changes, active network paths, process behavior, runtime privileges, and actual service exposure.
Attackers in 2026 increasingly rely on automated and AI-assisted tools to move quickly from vulnerability disclosure to exploitation. In some cases, exploitation attempts can occur within minutes. Legacy response models that rely on delayed patch cycles or manual prioritization are no longer sufficient to defend against modern attack scenarios.
A real-time, context-aware defense model is now required.
Runtime Context and eBPF as Core Drivers of Cloud-Native Security

Three Key Elements of Runtime Context
The key question in cloud-native security is no longer simply, “Does this vulnerability exist?” The more important question is:
“Can this vulnerability actually create risk in the current operating environment?”
Runtime context helps answer that question through three core elements.
First, execution status determines whether a vulnerable library or package is actually being loaded or executed. If a vulnerable component exists in an image but is never used in production, its remediation priority may be lower.
Second, reachability determines whether an attacker can actually access the affected workload. A vulnerability in an externally exposed service requires a different level of urgency than one isolated inside an internal network segment.
Third, behavioral signals help identify whether suspicious activity is already occurring. Abnormal system calls, unexpected network connections, unusual process execution, or privilege-related activity can indicate that a vulnerability is not just theoretical, but actively relevant.
The Strategic Value of eBPF for Runtime Security
eBPF, or Extended Berkeley Packet Filter, enables safe execution of programs inside the Linux kernel without modifying kernel source code. This makes it a powerful foundation for runtime security because it provides deep, non-intrusive visibility into system behavior.
With eBPF, security platforms can collect kernel-level events without requiring changes to application code. This allows organizations to observe process execution, file access, network activity, system calls, and privilege-related behavior with minimal performance impact.
In cloud-native environments, this visibility is critical. Runtime behavior is where real risk becomes visible. By observing the operating system directly, eBPF enables real-time network topology mapping, threat detection, and policy enforcement at the kernel level.
Building an Intelligent CNAPP Strategy with WERANA Veluna

Vulnerability Prioritization and Attack Surface Visibility
WERANA Veluna helps shift container and cloud-native security from static visibility to runtime-aware risk prioritization.
By combining CVE data from static scans with real-time runtime context, Veluna helps security teams identify which threats require immediate action. Instead of treating every vulnerability as equal, teams can focus on risks that are actively running, reachable, or showing suspicious behavior.
Veluna also visualizes actual communication paths through runtime-based network topology analysis. This helps security teams understand potential lateral movement paths before attackers can exploit them.
| Key Capability | How Runtime Context Is Used | Expected Outcome |
|---|---|---|
| Automated Asset Discovery | Automatically identifies containers, hosts, and cloud-native assets as they are created, and classifies them by C/S/O security level | Reduces unmanaged Shadow IT and improves asset management based on business criticality |
| Attack Surface Analysis | Visualizes application-to-application communication paths through eBPF-based tracing | Identifies lateral movement paths and potential exposure points before exploitation |
| Vulnerability Prioritization | Combines static CVE scan results with runtime signals such as activity and reachability | Reduces alert noise and helps teams focus on threats that require immediate action |
| Threat Detection and Response | Monitors abnormal behavior through MITRE ATT&CK-aligned runtime detection rules | Detects zero-day exploitation attempts, privilege abuse, and suspicious internal activity in real time |
Unified Visibility Beyond Container Security
A successful CNAPP strategy requires unified visibility across Kubernetes, containers, and hosts. WERANA Veluna provides a single platform for managing security events across distributed infrastructure environments.
Its MITRE ATT&CK-aligned detection rules help security teams move beyond simple anomaly detection. Instead of only identifying suspicious activity, Veluna provides actionable insight into the stage and nature of an ongoing attack.
This allows security teams to move from passive monitoring to proactive cloud security governance.
Conclusion: Optimizing Cloud Security Through Runtime-Aware Risk Identification
Listing vulnerabilities and resolving them one by one is no longer enough to protect modern cloud-native infrastructure.
In 2026, the effectiveness of cloud security depends less on how many vulnerabilities a tool can detect and more on how accurately it can identify which risks matter now. The combination of CWPP and runtime security is becoming an essential strategy for protecting dynamic cloud environments.
Organizations should evaluate whether their current security systems are identifying real operational risk — or whether critical signals are being buried under informational noise.
By adopting runtime context as part of their cloud security strategy, security teams can build a more complete, actionable, and resilient cloud-native security model.