Cloud News Now | August 2023
Welcome to the third edition of Cloud News Now from Aqua Security! In this month's issue, we're diving into the latest research from Aqua Nautilus, inspiring stories from our customers, and a glimpse into how Aqua is changing the cloud security game.
Aqua Nautilus #ThreatResearch
?? Kubernetes Exposed: One Yaml away from Disaster
Kubernetes has gained immense popularity among businesses in recent years due to its undeniable prowess in orchestrating and managing containerized applications. It consolidates your source code, cloud accounts, and secrets into a single hub. However, in the wrong hands, access to a company's k8s cluster could be not just harmful, but potentially catastrophic.?
Aqua Nautilus researchers uncovered Kubernetes clusters belonging to more than 350 organizations, open-source projects, and individuals, that were openly accessible and unprotected. At least 60% of these clusters were breached and had an active campaign with deployed malware and backdoors. Two main misconfigurations were among the things the team discovered. For a more comprehensive understanding of our findings and mitigation, read the blog.
?? PowerHell: Active Flaws in PowerShell Gallery Expose Users to Attacks
Recent findings from Aqua Nautilus researchers unveils critical vulnerabilities lurking within the PowerShell Gallery’s package policies, opening the doors to supply chain threats. PowerShell Gallery modules are commonly used as part of the cloud deployment process, especially popular around AWS and Azure, to interact with and manage cloud resources. Therefore, the installation of a malicious module could be fatal to organizations.?
Moreover, attackers can exploit another flaw, allowing them to discover unlisted packages and uncover deleted secrets within the registry, which users attempt to hide by unlisting their packages.?For a deeper understanding of the flaws, the risks, and suggested mitigations read more here.
领英推荐
For more threat intelligence and advice on cloud native security check out the Aqua Security blog here!
40% of the Fortune 100 are turning to Aqua.
In a recent conversation with Trinity Chavez at The New York Stock Exchange, Aqua's Co-Founder & CTO, Amir Jerbi, discussed how Aqua Security is changing the cloud security game and why 40% of the Fortune 100 are choosing Aqua. Tune into the conversation here.
Hear From Our Customers!
"From 120M risk findings to 50k and a reduction in attack surface by 99% in just months." - One of the world's largest telcos
Aqua is redefining cloud security excellence, one success story at a time! We take great pride in giving our customers peace of mind that they are secured from code to cloud and back. For more customer stories, check out Aqua's customer page.
Thank you for reading this month's edition of Cloud News Now! For all things Aqua, check out our website.
Sales Associate at American Airlines
1 年Great opportunity