Secure Your AWS EC2 Instance Metadata Service (IMDS)
August 8, 2023Read this review of IMDS, an important AWS EC2 service component, to understand its two versions and improve your AWS security.
CNAPPgoat: The Multicloud Open-Source Tool for Deploying Vulnerable-by-Design Cloud Resources
August 2, 2023Here’s all you need to know about CNAPPgoat, our open-source project designed to modularly provision vulnerable-by-design components in cloud environments.
An Unexpected Implication of Lambda Privileges
July 4, 2023Learn how a combination of AWS service usage and permissions discovered by Tenable Cloud Security may increase risk upon a certain non-compliance.
The Default Toxic Combination of GCP Compute Engine Instances
June 29, 2023By default, compute instances in GCP are prone to a toxic combination that you should be aware of, and can avoid and fix.
Shared Responsibility Model in the Cloud
June 21, 2023CSPs have embraced a shared responsibility model to define the security responsibilities for different components of the architecture.
Mastering the Art of Kubernetes Security
June 6, 2023With Kubernetes’ explosive adoption by the development community comes an urgent need to secure clusters and ensure their compliance effectively.
Uncovering 3 Azure API Management Vulnerabilities – When Good APIs Go Bad
May 4, 2023Learn how now-patched Azure API Management service vulnerabilities revealed by our research team enabled malicious actions.
Cloud Workload Protection (CWP) Best Practice – Focus on Impact, Not Volume
April 24, 2023How to do CWP right to prepare your organization and protect it from the next widespread vulnerability.
Terraform Lab: Taking the New VPC Endpoint Condition Keys Out for a Spin
April 3, 2023Our new open source Terraform project offers hands-on experience with VPC endpoints and demos AWS's new condition keys for securing EC2 instances
Federating Kubernetes Workloads with Cloud Identities
March 27, 2023Your K8s workloads legitimately need access to sensitive cloud resources – federated identities let you grant it easily and securely.
Navigating Cloud Security: Why Segregating Environments from Dev to Production is so Important
March 22, 2023Segregation in cloud environments is important for security — this post explores why and offers best practice tips for acting on it.
A New Incentive for Using AWS VPC Endpoints
March 9, 2023If you haven’t been using VPC endpoints until now, AWS' two new condition keys should make you consider doing so.