惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Google DeepMind News
Google DeepMind News
云风的 BLOG
云风的 BLOG
WordPress大学
WordPress大学
Vercel News
Vercel News
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
I
InfoQ
小众软件
小众软件
Recent Announcements
Recent Announcements
博客园 - 【当耐特】
The GitHub Blog
The GitHub Blog
大猫的无限游戏
大猫的无限游戏
美团技术团队
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
V
V2EX
J
Java Code Geeks
有赞技术团队
有赞技术团队
博客园 - 聂微东
B
Blog RSS Feed
博客园 - 司徒正美

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO
How Intruder finds what others miss in cloud security
David Gordon David Gordon · 2025-04-30 · via The Register - Security: CSO

CSO

Cloud doesn’t mean secure: How Intruder finds what others miss

A cloud security platform that manages the attack surface and security vulnerabilities in AWS

SPONSORED POST You’d be naïve to believe that the cloud is secure by default, and while most hosting services provide basic defenses, it’s not always clear what level of protection these provide.

Weak identity and access controls, inadequate encryption, insecure application programming interfaces (APIs), application and service misconfigurations, denial of service (DoS) attacks and insider threats – they can all lead to sensitive information stored in the cloud being lost or stolen.

The results of Dark Reading’s 2024 Strategic Security Survey indicate most enterprise IT and security managers are painfully aware of the problem. Almost half (49.6 percent) of those taking part reported they were worried about exploits targeting cloud service providers and a similar number (47.8 percent) expressed themselves wary about cloud services breaches and intrusions.

Additional defenses can provide some peace of mind though, which is what Intruder’s Cloud Security provides with its agentless cloud security scans. Intruder combines external vulnerability scanning with info from AWS accounts to find risks that other solutions might overlook, integrating with AWS to continuously find misconfigurations, insecure permissions and exposed secrets.

Those can include missing security controls and overly permissive privileges, IAM roles and access for example, as well as hardcoded keys, S3 buckets and other resources that could be exposed to the Internet. The platform also verifies encryption and backups to help ensure critical data is protected.

Intruder provides step by step remediation guidance to help companies quickly reconfigure those cloud accounts to mitigate the risks. It was designed to be user friendly and easy to use, with a simple pricing structure that helps customers understand what they are spending with no surprise charges further down the line.

For the moment Intruder’s cloud security scans are available for AWS environments, with support for Microsoft Azure, Google Cloud and other services using Kubernetes is coming later this year.

But even the best vulnerability checks won’t help if you don’t know what assets you have, especially in cloud environments where developers can spin up new services at any moment.

Intruder’s cloud sync automatically detects new assets as they are created, with the option to initiate scans immediately. It also supports custom rules for controlling which assets are added, and allows platform-native tags to be converted into Intruder tags for easier management. Cloud sync is available for Cloudflare, AWS, Microsoft Azure, and Google Cloud.

Intruder combines cloud security with vulnerability management and attack surface management in a single platform, incorporating its signature noise reduction to help businesses focus on the most important risks.

You can learn more and try a free 14 day trial of Intruder by clicking on this link.

Sponsored by Intruder