Security News

SecurityWeek to Host Virtual Cloud Security Summit on August 13, 2020
2020-08-12 16:17

SecurityWeek will host its 2020 Cloud Security Summit virtual event on Thursday, August 13, 2020. Through a fully immersive virtual environment, attendees will be able to interact with leading solution providers and other end users tasked with securing various cloud environments and services.

SecurityWeek to Host Cloud Security Summit Virtual Event on August 13, 2020
2020-08-12 12:18

SecurityWeek will host its 2020 Cloud Security Summit virtual eventon Thursday, August 13, 2020.

Half of IT teams can’t fully utilize cloud security solutions due to understaffing
2020-08-12 03:30

There are unrealized gaps between the rate of implementation or operation and the effective use of cloud security access brokers within the enterprise, according to a global Cloud Security Alliance survey of more than 200 IT and security professionals from a variety of organization sizes and locations. "CASB solutions have been underutilized on all the pillars but in particular on the compliance, data security, and threat protection capabilities within the service," said Hillary Baron, lead author and research analyst, Cloud Security Alliance.

Holding public cloud security to account
2020-08-10 15:15

The public cloud provides great flexibility and cost management for organizations, but what about security?

Capital One fined $80m for shoddy public cloud security. Yeah, same bank in that 106m customer-record hack
2020-08-07 01:22

Capital One must pay a trivial $80m fine for its shoddy public cloud security - yes, the US banking giant that was hacked last year by a miscreant who stole personal information on 106 million credit-card applicants in America and Canada. "The OCC took these actions based on the bank's failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud environment and the bank's failure to correct the deficiencies in a timely manner," the watchdog said in a statement on Thursday.

Threat Stack Cloud Security Platform extends security observability to AWS Fargate tasks
2020-08-04 23:45

Extending the observability provided by the Threat Stack Cloud Security Platform to AWS Fargate tasks can help Threat Stack customers detect threats and maintain compliance across all areas of their cloud infrastructure. The Threat Stack Cloud Security Platform collects and correlates security telemetry from the cloud management console, host, containers, orchestration, managed container services and applications, giving Threat Stack customers a view into their entire cloud environment.

Bridgecrew: Our mission is to set cloud security free
2020-07-23 18:00

It's no secret misconfiguration is now the cloud's biggest security worry, although tying IaC to specific cloud security incidents is much harder to assess - misconfiguration can happen via any interface and not only IaC. One way to grasp the scale of the issue is to infer the answer by looking at the IaC templates on public repositories such as GitHub - an approach used by Palo Alto's Unit 42 earlier this year when it uncovered 199,000 insecure templates, including many high and medium-level flaws that would lead to serious misconfigurations. "Misconfigured cloud resources are likely the main root cause for unintended exposure of sensitive data for cloud native companies. Misconfigured public interfaces, exposed secrets, and encrypted databases are just a few very common examples where companies have made bad calls when configuring their cloud infrastructure."

An effective cloud security posture begins with these three steps
2020-07-10 05:00

Public cloud adoption continues to surge, with roughly 83% of all enterprise workloads expected to be in the cloud by the end of the year. While cloud adoption has transformed the way applications are built and managed, it has also precipitated a radical rethink of how to approach security.

Ending the Cloud Security Blame Game
2020-07-08 05:34

Security is primarily your responsibility – with help from the cloud provider.

Cloud Security Alliance and ISSA unite to build, support, and strengthen the cybersecurity community
2020-06-30 23:45

The Cloud Security Alliance and the International Systems Security Association announced that the two parties have signed a memorandum of understanding to collaborate on a variety of initiatives with the goal of both supporting and strengthening the cybersecurity profession. "Our partnership with ISSA heralds an exciting opportunity for both organizations to collaborate and bring our strengths and unique sets of expertise to the table to benefit cloud and cybersecurity professionals across the spectrum," said Jim Reavis, co-founder and CEO, Cloud Security Alliance.