Hunting for signs of persistence in the cloud: an IR guide following the CircleCI incident
Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident

4276 articles
4276 ARTICLES
Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident


Open Source Program Offices (OPSO) are popping up all over, in recognition of the facts on the ground: open source software (and I would argue open standards as well) plays an enormous role in building and maintaining the software that increasingly drives the planet.

Wiz announces availability of new regional data center and adds support for Essential Eight controls.

Snyk IaC security takes a developer-first, application-centric approach to finding and fixing vulnerabilities in cloud infrastructure from the time infrastructure is defined in code, through to when resources are running in the cloud.

Learn about key AppSec investments Snyk made in 2022 to improve performance, add new ecosystems, and support the enterprise.

Open Policy Agent (OPA) adopts Chainguard Images to secure systems from vulnerabilities. Others like Tailscale and Vietnam-based VPBank are also following suit.

Looking under the Wolfi hood. Chainguard Images now multi-platform with added 64-bit Arm (arm64) support and continues to expand set of available architectures.

Now that it’s a new year, let’s take a look back at some of the amazing 2022 Snyk developer security platform highlights.

Hear from security leaders about their plans, strategies, and priorities for the new year.

On January 4, CircleCI, an automated CI/CD pipeline setup tool, reported a security incident in their product by sharing an advisory.Learn about this incident, next steps, and about supply chain security.

Keyless software signing uses ephemeral keys (not cryptographic) to sign and verify software. Get started using Chainguard Enforce Signing, powered by Sigstore.

In this second blog post, we will discuss lateral movement risks from Kubernetes to the cloud. We will explain attacker TTPs, and outline best practices for security practitioners and cloud builders to help secure their cloud environments and mitigate risk.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy