Uncovering 3 Azure API Management Vulnerabilities – When Good APIs Go Bad
May 4, 2023Learn how now-patched Azure API Management service vulnerabilities revealed by our research team enabled malicious actions.
Cloud Workload Protection (CWP) Best Practice – Focus on Impact, Not Volume
April 24, 2023How to do CWP right to prepare your organization and protect it from the next widespread vulnerability.
Terraform Lab: Taking the New VPC Endpoint Condition Keys Out for a Spin
April 3, 2023Our new open source Terraform project offers hands-on experience with VPC endpoints and demos AWS's new condition keys for securing EC2 instances
Federating Kubernetes Workloads with Cloud Identities
March 27, 2023Your K8s workloads legitimately need access to sensitive cloud resources – federated identities let you grant it easily and securely.
Navigating Cloud Security: Why Segregating Environments from Dev to Production is so Important
March 22, 2023Segregation in cloud environments is important for security — this post explores why and offers best practice tips for acting on it.
A New Incentive for Using AWS VPC Endpoints
March 9, 2023If you haven’t been using VPC endpoints until now, AWS' two new condition keys should make you consider doing so.
Managing Cloud Compliance and Security Posture with Cloud Compliance Tools
March 8, 2023Why compliance and access security in the public cloud are so challenging – and how carefully-chosen CSPM tools can help.
How to Implement CIEM – A Checklist
February 8, 2023What differentiates a CIEM solution from other cloud security platforms, and how should a CIEM be used in an organization? Read on to find out.
How Attackers Can Exploit GCP’s Multicloud Workload Solution
February 1, 2023A deep dive into the inner workings of GCP Workload Identity Federation, taking a look at risks and how to avoid misconfigurations.
EmojiDeploy: Smile! Your Azure web service just got RCE’d ._.
January 19, 2023The Tenable Cloud Security research team discovered a remote code execution vulnerability affecting Microsoft Azure cloud services such as Function Apps, App Service, Logic Apps and others, as well as other cloud sovereigns.
Microsoft Azure Virtual Machines: Public IP Configuration Is Not Always As It Seems
January 16, 2023If you’re not familiar enough with the SKU attribute of the Azure public IP address, you may think you’re configuring your virtual machines as public to the internet … but you aren’t.
Why JIT Access is an Essential Part of Cloud Security
January 8, 2023Automating JIT in the cloud is win-win for improving security and business productivity -- and cracks a nut that PAM can’t.