#Cspm

Pen Test PartnersPTP@infosec.exchange
2025-11-25

Cloud compliance dashboards, CNAPP, and CSPM can all show green, but they don't show your entire attack surface.

The issue is not with the dashboards, but with the blind spots that lie outside their view, such as leaked developer personal access tokens or overprivileged pipelines that do not appear as non-compliant.

In this blog post, Joe Durbin looks at those gaps around tokens, pipelines, and third-party build services. He explains how human-led configuration reviews and custom threat actor simulations work alongside provider tools to show and test your actual attack surface.

📌pentestpartners.com/security-b

#cloudsecurity #cloudnative #devsecops #cnapp #cspm #cybersecurity

Josh Leeitsjoshlee_
2025-09-29

When it comes to cyber security, the tools you use can be the difference between preventing breaches - or not even knowing if anything happened all.

Here are some kinds of tools I like to use. I think they'll be helpful for you, too.

medium.com/@heyjoshlee/cspm-ci

2025-09-19

☁️ Cloud Security Tools — Essential Toolkit for Modern Teams 🛡️🚀

Cloud environments introduce new risks and require specialized tooling to secure workloads, configurations, and data. Use a mix of CSP-native and third-party tools to cover posture management, runtime protection, identity, and visibility. Key categories and examples: Cloud Security Posture Management (CSPM) — Prisma Cloud, Dome9, Wiz for misconfig & compliance checks 🔍; Cloud Workload Protection (CWPP) — CrowdStrike, Trend Micro, Aqua for container and VM runtime defense 🐳🛡️; Cloud Access Security Broker (CASB) — Netskope, Microsoft Defender for Cloud Apps for SaaS visibility & data control ☁️🔐; Identity & Access Management — AWS IAM/Azure AD hardening, BeyondTrust, Okta for strong auth & least privilege 🔑; Threat Detection & SIEM — Splunk, Sumo Logic, Datadog + cloud-native logging for alerting and forensics 📊; Vulnerability & Configuration Scanning — Qualys, Tenable, Trivy for images and infra-as-code scanning ⚙️; Secrets Management — HashiCorp Vault, AWS Secrets Manager for safe key handling 🔐; and Supply-chain & CI/CD security — Snyk, Checkov, GitHub Advanced Security to catch insecure deps and pipelines 🧩.

⚠️ Disclaimer:
For educational & defensive use only. Evaluate tools against your cloud provider, compliance needs, and threat model before deploying. Always test changes in staging before production. 🚫🔒

#CloudSecurity #CSPM #CWPP #IAM #DevSecOps #InfoSec #Cloud #CyberSecurity #SecurityTools #Compliance #ContainerSecurity ☁️🛡️

2025-08-29

Киберугрозы в первом полугодии 2025 года: анализ векторов атак на облачные и гибридные инфраструктуры

Привет, Хабр! Меня зовут Юрий Наместников, я руковожу Cloud Security Operations в Yandex Cloud, и сегодня мы поговорим о результатах анализа кибератак в первом полугодии 2025 года. За первые шесть месяцев 2025 года мы зафиксировали более 25 тыс. попыток кибератак на облачные и гибридные инфраструктуры. В этом отчёте с результатами нашего исследования рассказываем об актуальных угрозах и тенденциях, которые видели как в собственном контуре, так и в целом у российских компаний в первом полугодии

habr.com/ru/companies/yandex_c

#безопаность #облака #ycdr #cspm #kspm #mitre #mitre_attack

Mor Ashermorasher
2025-03-07

Cloud misconfigurations: a gap calling for the thief.

Top and common cloud misconfigurations you will find in a typical cloud deployment.

While many invest great resources in applications vulnerabilities (rightfully), many tend to neglect configuration hardening. A big mistake.

api.cyfluencer.com/s/top-cloud

isecjobs.com => foorilla.cominfosec_jobs
2024-10-21

HIRING: Senior Information Security Architect (m/f/d) / Aschaffenburg, Berlin
💰 EUR 80K+

👉 isecjobs.com/J511529/

isecjobs.com => foorilla.cominfosec_jobs
2024-10-14

HIRING: Senior Information Security Architect (m/f/d) / Aschaffenburg, Berlin
💰 EUR 80K+

👉 isecjobs.com/J511529/

isecjobs.com => foorilla.cominfosec_jobs
2024-10-07

HIRING: Senior Information Security Architect (m/f/d) / Aschaffenburg, Berlin
💰 EUR 80K+

👉 isecjobs.com/J511529/

isecjobs.com => foorilla.cominfosec_jobs
2024-09-30

HIRING: Senior Information Security Architect (m/f/d) / Aschaffenburg, Berlin
💰 EUR 80K+

👉 isecjobs.com/J511529/

isecjobs.com => foorilla.cominfosec_jobs
2024-09-27

HIRING: Senior Information Security Architect (m/f/d) / Aschaffenburg, Berlin
💰 EUR 80K+

👉 isecjobs.com/J511529/

2024-07-24

What security products can you recommend for securing cloud deployments (AWS in particular)? I'm not sure if I can tell actual good and sensible products apart from hype marketing with the acronym and buzzword laden offerings. XDR/CDR, CNAPP, CSPM, CWPP, CIEM, ...

Insights from people with hands on experience are much appreciated!

#aws #k8s #cloud #security #xdr #cnapp #cspm #siem

2024-07-22

AWS Security Hub als zentrales Sicherheits-Orchestrierungstool 🔐

Der Dreh- und Angelpunkt hinsichtlich der Sicherheit in der AWS-Cloud ist der AWS Security Hub, der als zentrales Sicherheits-Orchestrierungstool alle AWS Security Services aggregiert. Der Hub gibt somit einen gesamtheitlichen Cloud-Sicherheitsstatus wieder und initiiert SicherheitsOrchestrierungs-, Automatisierungs- und Antwort-Workflows ♻

2024-07-15

Cloud Security Posture Management (CSPM) in 2024: Benefits & AWS Setup

Cloud Security Posture Management (CSPM) represents a proactive approach to cloud security, focusing on the continuous monitoring and assessment of cloud infrastructure.

At its core, CSPM involves the automated detection of misconfigurations, vulnerabilities, and non-compliance issues within a cloud environment. 

Steps to Configure CSPM with AWS
Configuring Cloud Security Posture Management (CSPM) with AWS involves several steps to ensure a comprehensive security posture. This process begins with the initial setup of CSPM tools, followed by integration with AWS services, and concludes with configuring continuous monitoring and alerting mechanisms.

Full Read - knowcybersec.xyz/2024/07/Cloud

#CSPM #cloudsecurity #cybersecurity #awssecurity

2024-07-11

A pleasure to be back moderating webinars, first one for a few years today for SC UK with speakers from Picus Security and AWS talking cloud security, automation, attack simulation and #cspm

insight.scmagazineuk.com/beyon

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst