Security News

Capital One fined $80m for shoddy public cloud security. Yeah, same bank in that 106m customer-record hack
2020-08-07 01:22

Capital One must pay a trivial $80m fine for its shoddy public cloud security - yes, the US banking giant that was hacked last year by a miscreant who stole personal information on 106 million credit-card applicants in America and Canada. "The OCC took these actions based on the bank's failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud environment and the bank's failure to correct the deficiencies in a timely manner," the watchdog said in a statement on Thursday.

Threat Stack Cloud Security Platform extends security observability to AWS Fargate tasks
2020-08-04 23:45

Extending the observability provided by the Threat Stack Cloud Security Platform to AWS Fargate tasks can help Threat Stack customers detect threats and maintain compliance across all areas of their cloud infrastructure. The Threat Stack Cloud Security Platform collects and correlates security telemetry from the cloud management console, host, containers, orchestration, managed container services and applications, giving Threat Stack customers a view into their entire cloud environment.

Bridgecrew: Our mission is to set cloud security free
2020-07-23 18:00

It's no secret misconfiguration is now the cloud's biggest security worry, although tying IaC to specific cloud security incidents is much harder to assess - misconfiguration can happen via any interface and not only IaC. One way to grasp the scale of the issue is to infer the answer by looking at the IaC templates on public repositories such as GitHub - an approach used by Palo Alto's Unit 42 earlier this year when it uncovered 199,000 insecure templates, including many high and medium-level flaws that would lead to serious misconfigurations. "Misconfigured cloud resources are likely the main root cause for unintended exposure of sensitive data for cloud native companies. Misconfigured public interfaces, exposed secrets, and encrypted databases are just a few very common examples where companies have made bad calls when configuring their cloud infrastructure."

An effective cloud security posture begins with these three steps
2020-07-10 05:00

Public cloud adoption continues to surge, with roughly 83% of all enterprise workloads expected to be in the cloud by the end of the year. While cloud adoption has transformed the way applications are built and managed, it has also precipitated a radical rethink of how to approach security.

Ending the Cloud Security Blame Game
2020-07-08 05:34

Security is primarily your responsibility – with help from the cloud provider.

Cloud Security Alliance and ISSA unite to build, support, and strengthen the cybersecurity community
2020-06-30 23:45

The Cloud Security Alliance and the International Systems Security Association announced that the two parties have signed a memorandum of understanding to collaborate on a variety of initiatives with the goal of both supporting and strengthening the cybersecurity profession. "Our partnership with ISSA heralds an exciting opportunity for both organizations to collaborate and bring our strengths and unique sets of expertise to the table to benefit cloud and cybersecurity professionals across the spectrum," said Jim Reavis, co-founder and CEO, Cloud Security Alliance.

IBM Acquires Cloud Security Company Spanugo
2020-06-16 11:35

IBM has announced a definitive agreement to acquire cloud cybersecurity posture management solutions provider Spanugo. Spanugo's technology allows organizations to demonstrate compliance in real time, while also helping them continuously improve their cloud security to ensure that attacks can be repelled.

FireEye Cloudvisory: Control center for multi-cloud security management
2020-05-14 03:00

FireEye, the intelligence-led security company, announced the availability of FireEye Cloudvisory, a control center for cloud security management across any security environment - private, public and hybrid. Fully integrated into the broader FireEye cloud security portfolio, Cloudvisory now offers customers instant deployment across their cloud infrastructures, and further capabilities in security analytics through FireEye Helix and advanced threat detection through FireEye Detection On Demand.

Cloud Security Company Ermetic Emerges From Stealth Mode
2020-05-08 15:49

Cloud security company Ermetic emerged from stealth mode this week with a platform that automates detection and remediation of identity and access-based risks. The company's analytics-based platform, which is available immediately, is designed to automatically discover all identities in the cloud, and analyzes policies and permissions in an effort to identify and remediate access risks.

Podcast: Shifting Cloud Security Left With Infrastructure-as-Code
2020-05-08 13:00

Companies are increasingly dealing with a slew of security and compliance issues across cloud services and containers - from AWS to Azure to Google Cloud. Infrastructure-as-Code security capabilities can help companies shift their cloud security "Left" to improve developer productivity, avoid misconfigurations and prevent policy violations.