惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
U
Unit 42
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
腾讯CDC
I
InfoQ
GbyAI
GbyAI
博客园_首页

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
The good, the bad, and the vulnerable
Merav Bar, Amitai Cohen · 2023-10-10 · via Wiz Blog | RSS feed

Vulnerability management in the cloud presents new challenges and opportunities. The Wiz threat research team presents a new report focusing on how the ability to manage vulnerabilities in the cloud requires an understanding of both Application Security (AppSec) and Cloud Security (CloudSec). Using recent vulnerabilities as examples, the report explores insights on vulnerability management in cloud environments, along with Wiz’s methodology for using vulnerability intelligence. 

The good

Let's begin by exploring the positive aspects of vulnerability management in cloud environments. One notable advantage is the ease of reducing the attack surface. Cloud environments offer opportunities for minimizing the attack surface through techniques like employing smaller images. Additionally, the adoption of serverless and Software-as-a-Service (SaaS) models has accelerated and simplified the patching process. It's worth mentioning that many third-party software vulnerabilities have less impact in the cloud, and we'll delve into this further. 

The bad

Despite the advantages mentioned above, certain vulnerabilities can have a greater impact in cloud environments compared to on-prem environments. While SaaS and serverless architectures offer convenience, the overall complexity increases when dealing with their appliance counterparts. In such cases, organizations are reliant on vendors for patches, and achieving visibility can become challenging. 

The vulnerable

Now, let's explore how we determine which vulnerabilities truly matter in cloud environments. With the multitude of Common Vulnerabilities and Exposures (CVEs) in the cybersecurity landscape, prioritizing which vulnerabilities to patch becomes crucial to any organization. When analyzing vulnerabilities, we must consider the technologies prevalent in the cloud and the attack surface they expose. Additionally, it is essential to assess the value of a vulnerability to threat actors targeting cloud environments in light of their potential goals. 

For example, the following graph serves as a model for estimating vulnerability impact in the cloud based on perceived “tech value” and initial-access potential. 

Many vulnerabilities exist in cloud environments but in practice have limited impact due to the cloud’s unique nature and design. 

Learn more

To learn more about how to determine which technologies hold the most potential value to attackers, as well as how to gauge the impact and likelihood of vulnerabilities in your cloud environment, check out our talk from fwd: cloudsec. And click the button below to download the report!