










Every change in a cloud environment creates new security decisions.
A new infrastructure as code (IaC) template needs to be validated. Cloud permissions need to be reviewed. An application release introduces new cloud interactions. A Kubernetes cluster needs protection before it goes into production. Individually, these are routine tasks. Together, they create growing operational friction that makes cloud security harder to scale.
This month's CrowdStrike Falcon® Cloud Security innovations reduce that friction. New capabilities strengthen IaC security, streamline cloud identity investigations and remediation, provide deeper application context, expand agentless workload visibility, and simplify Kubernetes deployment. These updates, all of which are generally available, help security teams spend less time managing security operations and more time reducing cloud risk.
Cloud infrastructure is increasingly managed as code. Terraform templates, Kubernetes manifests, IAM policies, and cloud configurations define how cloud environments are built, making IaC one of the earliest opportunities to identify misconfigurations and vulnerabilities before infrastructure is deployed.
Falcon Cloud Security now brings IaC security directly into Visual Studio Code and IntelliJ. Teams receive immediate feedback as cloud infrastructure is authored so they can identify misconfigurations and policy violations before changes progress through deployment workflows. This feedback includes remediation guidance so issues can be resolved while infrastructure is built.
Organizations can also extend Falcon Cloud Security with Custom Rego Rules for IaC scanning. Security and platform teams can create organization-specific security and compliance policies alongside CrowdStrike's built-in detections. Custom rules integrate seamlessly with the Falcon Cloud Security CLI and surface in the Falcon console alongside native findings. This enables teams to consistently enforce infrastructure security standards and manage findings across cloud environments.
Figure 1. Creating custom Rego rules for IaC security
Cloud permissions continuously evolve as organizations deploy new applications, automate infrastructure, and integrate additional cloud services. Determining who has access to what — and whether that access is appropriate — often requires time-consuming investigation across identities, policies, and cloud resources.
Falcon Cloud Security expands cloud infrastructure entitlement management (CIEM) with capabilities that simplify investigation and remediation. Permission Querying extends Graph Explorer beyond existing risk findings so analysts can explore cloud identity relationships even when no security finding exists. Security teams can quickly answer operational questions such as which resources an identity can access, who has access to a particular resource, and how permissions are inherited across an environment.
CrowdStrike also introduces least privilege remediation. Rather than requiring administrators to manually create IAM policies, Falcon Cloud Security now generates least-privilege IAM policies based on observed permission usage with a single click. This helps organizations reduce excessive permissions faster while accelerating least-privilege adoption.
Figure 2. Explore identity permissions in Graph Explorer with context
Modern applications increasingly interact with cloud infrastructure through privileged identities, cloud APIs, secrets, networking services, and infrastructure automation. Understanding application risk requires understanding how applications are designed to interact with these cloud resources.
Falcon Cloud Security expands application security posture management (ASPM) with capabilities that automatically provide that context. New Admin Actions correlate application code analysis with CIEM insights to identify the cloud control plane actions an application is designed to perform, including IAM administration, secrets management, networking, infrastructure provisioning, and access to sensitive data. Comparing intended behavior with granted permissions helps organizations identify excessive application privileges and assign remediation to the teams responsible for the application.
Falcon Cloud Security also introduces the first release of API Findings, which automatically discover inbound and outbound APIs directly from application source code. Support includes REST APIs, gRPC services, serverless functions, and message brokers. This gives security teams greater visibility into application communication paths, service dependencies, and API exposure without requiring manual documentation.
Figure 3. Investigating an application performing administrative behavior on cloud infrastructure
Protecting cloud workloads shouldn't introduce additional operational complexity. Falcon Cloud Security now extends Agentless VM Scanning to Microsoft Azure, enabling organizations to assess Azure virtual machines for vulnerabilities without deploying agents. This expands existing AWS support while providing the same consistent agentless assessment workflow across cloud providers.
CrowdStrike is also introducing a new Kubernetes Deployment Wizard, which guides administrators through deploying Falcon Cloud Security in minutes across Amazon EKS, Azure Kubernetes Service (AKS), Google Kubernetes Engine (GKE), Red Hat OpenShift, and other CNCF-conformant Kubernetes environments.
The guided experience generates a production-ready installation script based on deployment selections. This reduces manual configuration while helping organizations deploy Kubernetes protection more consistently across cloud environments.
See how to deploy Kubernetes protection in minutes:

Every infrastructure deployment, identity change, application release, and workload rollout creates new security decisions. As cloud environments continue to evolve, the critical challenge is keeping pace with change without increasing operational complexity.
These Falcon Cloud Security enhancements reduce the day-to-day effort required to secure cloud environments. By simplifying infrastructure security, identity governance, application analysis, and workload protection, organizations can spend less time on repetitive operational tasks and more time reducing cloud risk.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。