Gomboc.ai的动态

Gomboc.ai转发了

查看Matthew Sweeney的档案,图片

CPO & Co-Founder @ Gomboc.ai | Leader | Customer champion | Coach | Architect | Driving innovation through people and technology

Cloud Security Nightmare: Shared Responsibility Gone Wrong https://lnkd.in/gEXaV4bb New research reveals a major security vulnerability in AWS’ Application Load Balancer. The issue? People weren't validating token signers, a common misstep in cloud setups. This highlights a fundamental problem with the shared responsibility model:?cloud providers often push the burden of security onto their customers.?Keeping up with constant API changes and documentation updates is nearly impossible. Since cloud providers can’t see their customers’ environments, the burden falls to cloud consumers. How can we ensure secure cloud environments when even minor configuration oversights can lead to major breaches? To my friends in the security community: - How do you help your companies (or customers) manage through these types of situations? - Where do you feel the pain of mastering all of this cloud configuration knowledge? - What could we do to make these types of situations more manageable? It’s time to leverage AI to “RTFM” continuously for us and put information at the fingertips of practitioners to make our clouds efficient and secure. #cloudsecurity #aws #sharedresponsibility #cybersecurity

An AWS Configuration Issue Could Expose Thousands of Web Apps

An AWS Configuration Issue Could Expose Thousands of Web Apps

wired.com

Matthew Sweeney

CPO & Co-Founder @ Gomboc.ai | Leader | Customer champion | Coach | Architect | Driving innovation through people and technology

3 个月
Curtis Deptuck

Dad. Tech Enthusiast. Innovator.

3 个月

In ALBeast, the seperation of responsibilities between the developer codebase and the "infrastructure" is more than likely the root cause. It's a pretty classic story, both sides assumed they were secure and validating while neither side was. I see that narrow viewed not my problem mentality almost everyday and AI is just going to be another crutch for what is an ignorant behaviourism that needs to be fixed tbh. As a developer or anyone really, if you chose to build something in the cloud, you choose to operate and maintain it and yes you need some minimal level of understanding of it end to end. These are not boxed products you put on a shelf and forget about it because the fault isolation domain is a single customer. That's the problem that needs addressing.

回复
Jonathan Cran

Founder | Product & Engineering Leader

3 个月

It’s time to leverage AI to “RTFM” continuously for us and put information at the fingertips of practitioners to make our clouds efficient and secure. ^ YES

Iftach Ian Amit

CEO & Co-Founder @ Gomboc.ai | 2x ex-CSO/CISO

3 个月

Well said!

回复
Lidiia Mandrovna

R&D Delivery Manager at Apriorit | Custom software development | Expertise in SaaS, XDR, EDR, SIEM, SOAR, DLP |Kernel development | WEB development | MDM and MAM solutions | Embedded Systems | Reverse Engineering

3 个月

Insightful!

回复
查看更多评论

要查看或添加评论,请登录