惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
Jina AI
Jina AI
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
N
Netflix TechBlog - Medium
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
The Blog of Author Tim Ferriss
D
Docker
博客园 - 聂微东
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
量子位
宝玉的分享
宝玉的分享
博客园 - 司徒正美
The Cloudflare Blog
G
Google Developers Blog
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
5 Cloud Security Predictions for 2023
Luke (hakluke) Stephens · 2023-08-07 · via Wiz Blog | RSS feed

The aftermath of COVID19 is still sending shockwaves through our society, new expectations of location freedom are changing the way we work, AI is changing the way we work, and the whole security industry is just doing their best to hold on. For this reason, there has never been a more difficult time to predict the future of… well, anything! But especially something as dynamic as cloud security. We're still going to give it our best shot. 

 Are you ready to dive in with me? Great! Let's check out the 5 cloud security predictions for 2023 that are bound to keep you on your toes. 

The Cloud-Native Shift: Kubernetes, the Conductor of the Multi-Cloud Orchestra 

The cloud-native shift is a dance we've all been performing for a while now, and it's not stopping anytime soon. In fact, it's still gaining momentum. With Kubernetes becoming the default orchestration stack for multi-cloud environments, we're seeing more and more vulnerable clusters out there. If you're looking for something to help you here, it might be worth checking out Wiz's Kubernetes security solution

 What can you do to protect your precious Kubernetes clusters? You can start by keeping up-to-date with security best practices and ensuring your team is well-trained. The Kubernetes documentation has a lot of details about best security practices and hardening. This is a good place to start. 

Software Supply Chain Security: The Looming Threat to Developer Laptops 

Remember when we only had to worry about the server room's security? Yeah, me neither. In 2023, we predict that software supply chain security will keep climbing up the threat class ladder. Now even developer laptops are in scope (see: the LastPass breach). 

Supply chain security is a tough one to solve, but it helps to vet suppliers from a security standpoint. Now more than ever, adversaries are recognizing supply chain attacks as a viable entrypoint to an organization. MSPs are prime targets because, by design, they have access to the networks of their customers. It's no surprise that attacks against MSPs are on the rise

Artificial Intelligence Attacks: Cloud's Newest Friend and Foe 

I don't believe AI will replace humans in cybersecurity in the immediate future. Rather, I think it will augment their abilities, which is an opinion shared by this article. This applies to both attackers and defenders, so it's important that the attackers fully embrace AI so as not to give attackers an unfair advantage. 

We've already seen AI augmented phishing campaigns, and they're only going to get more sophisticated. What AI has done is given attackers the capability to scale out attacks that previously required human work, such as customizing phishing attacks to target a specific person's interests. 

AI has also opened up a whole new attack surface: LLM prompt injection, where attackers use specially crafted prompts to convince chatbots to reveal their secrets and bypass security controls. Due to the unpredictable nature of LLMs, this is currently quite difficult to defend against and has led to some interesting vulnerabilities, one being the discovery of "Sydney", the name of Bing's new chatbot

It will only be a matter of time before major cloud providers start using AI chatbots to help you manage your cloud. Imagine being able to type "initialize a new S3 bucket to host a static website, then set up Cloudfront in front of it and then point app.example.com to the Cloudfront instance", instead of having to perform these tasks manually. While this will save time, it may also cause some security settings to be overlooked, which could compromise security of the infrastructure and applications. 

The Rise of Consolidated and Affordable Tools: A Golden Opportunity for Businesses 

As the overall economy pushes for consolidation, cheaper and consolidated tools are poised to win out. Not only is this more cost-effective, it may also be more convenient for security teams because it negates the need to implement half-baked integrations between tools. 

The pros: 

  • Tools become more affordable. 

  • Integrations become less of an issue. 

  • Available tools will be high quality, belonging to large organizations. 

The cons: 

  • The cybersecurity vendor market will be further dominated by larger organizations, making it more difficult for smaller vendors to compete or innovate. 

  • Security teams may be forced into a "one-size-fits-all" approach, having to follow the prescribed or implied processes that are determined by their tooling. 

The End of the Cryptomining Gold Rush 

Cryptocurrency prices have dropped and cryptominers have become less profitable. The more criminally minded cryptominers won't throw in the towel. Instead, they'll shift their focus to cloud ransomware, data exfiltration, and more targeted attacks on organizations. 

 What does that mean for security teams? More attacks, and more sophistication in those attacks. 

Conclusion 

There you have it! Those are our top 5 cloud security predictions for 2023. We can't say for sure whether all of these will come true, but it's always wise to stay ahead of the game. 

For now, keep your eyes peeled and your security solutions up-to-date. With Wiz by your side, we can tackle whatever the future throws at you. And remember, "An ounce of prevention is worth a pound of cure."