惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
罗磊的独立博客
S
Secure Thoughts
Schneier on Security
Schneier on Security
博客园 - Franky
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
爱范儿
爱范儿
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
PCI Perspectives
PCI Perspectives
Google DeepMind News
Google DeepMind News
S
Security Affairs
SecWiki News
SecWiki News
博客园 - 聂微东
Security Archives - TechRepublic
Security Archives - TechRepublic
Google Online Security Blog
Google Online Security Blog
H
Heimdal Security Blog
S
Security @ Cisco Blogs
Engineering at Meta
Engineering at Meta
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cloudbric
Cloudbric
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
V
Visual Studio Blog
P
Proofpoint News Feed
Project Zero
Project Zero
T
Threat Research - Cisco Blogs
Webroot Blog
Webroot Blog
Blog — PlanetScale
Blog — PlanetScale
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
W
WeLiveSecurity
Last Week in AI
Last Week in AI
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence
有赞技术团队
有赞技术团队
S
Securelist
GbyAI
GbyAI
Application and Cybersecurity Blog
Application and Cybersecurity Blog
C
CERT Recently Published Vulnerability Notes
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Cyberwarzone
Cyberwarzone
B
Blog RSS Feed
P
Palo Alto Networks Blog
H
Hacker News: Front Page
D
Docker
雷峰网
雷峰网
Latest news
Latest news
Microsoft Security Blog
Microsoft Security Blog

DataBreachToday.com RSS Syndication

Ex-Threat Intel Exec Accuses IBM and AT&T of Hiding Hacks Bipartisan AI Bill Targets Frontier Labs and State Regulators Passengers Seek Full Appeals Court Review in CrowdStrike Case What Trump's AI Executive Order Means for Healthcare Sector Data breach detection, prevention and notification Data breach detection, prevention and notification Data breach detection, prevention and notification Data breach detection, prevention and notification What DORA, AI Oversight, and Cloud Dependency Mean for Business and Risk Leaders AI Generated Code Is Expanding the Attack Surface Live Webinar | Defending the Modern Attack Path: How Integrated Security Stops Multi-Vector Threats Why Hospitals Must Rethink Cyber Resilience Live Webinar | Defending the Modern Attack Path: How Integrated Security Stops Multi-Vector Threats The Privacy Risks of Embedded, Shadow AI in Healthcare Why Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight The End of Static Security: Why AI Demands Real-Time Microsegmentation AI Agents Are the New Insiders Demystifying Claude: Signal vs. Speculation Integrity or Innovation? Mixed Signals in Trump's Exec Orders AI Is Reshaping Cybersecurity Training Priorities Claude Mythos 5 Can Build Exploits But Can't Power Campaigns Health Cyberthreat Sharing Is Advancing But Gaps Persist Are Small Models Closing the Gap on Frontier AI Cyber Tools? Securing AI in Financial Services with Zero Trust Beyond the Inbox: Defending Against AI-Enabled Social Engineering Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | 6 Layers Standing Between Your Enterprise and AI Risk How AI Governance Protects Patient Care and Sensitive Data Election Systems Are Now a Persistent Cyber Target Cryptohack Roundup: Sentencing in $97M Laundering Case Breach Roundup: CISA Says Agencies Should 'Patch Smarter' Joint Commission Certification Targets Healthcare AI Risks DOJ, FBI Seize 13 Domains in Chinese Recruitment Op Vietnamese Digital Spies Look for Domestic Targets A Security Gets $37M to Thwart Weaponized AI With Automation German Court: Google Liable for AI Summaries Google Sues Chinese Phishing Service Over Gemini Abuse Policy as Code: From Documents to Machine Intelligence Anthropic Limits on OT Access to Mythos Draw Criticism ISMG Editors: Anthropic Unleashes Claude Mythos 5 Ozempic Drug Maker Loses Clinical Trial Data in Hack ISACA Survey: AI Adoption Is Rising, Visibility Is Not Webinar | Frontier AI and Identity Security in Financial Services US Pulls the Plug on Anthropic's Top AI Models US Anthropic Export Controls Sparks Sharp EU Reaction 1Password Buys Apono to Expand AI Access Governance NewCore Launches With $66M to Rebuild Identity for AI Agents GovSec Summit USA 2026: Cyber Resilience Amid Fiscal Reality Labcorp Agrees to Pay $35M to Settle AMCA Data Breach Mythos Shutdown Contains a Message: Don ShinyHunters Hits Universities Via Oracle Zero-Day How FDA US FCC Eases Router Ban for Cable ISPs Chinese Hacking Firm Upgrades With New Windows Backdoor South Korea Fines Coupang $409M Over Massive Data Breach Cyber Resilience Summit Dallas Prioritizes Risk Management Hacker: Restore Fable and Mythos Access, Cybersecurity Leaders Urge Live Webinar | Behind Dell’s AI Infrastructure Performance Rokarolla Android Banking Trojan Enables Device Takeover Ent Raises $100M to Reinvent Endpoint Security for AI Era The AI Accountability Gap CIOs Can Chinese Espionage Actor Abuses Email Rules to Steal Research Data AWS Unveils Continuum to Fight Vulnerability Backlog Quantum-Safe Cryptography Isn SpaceX Bets Big on AI Coding With $60B Cursor Deal Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data Mastra AI Framework Poisoned in npm Supply-Chain Attack Cyberspace Locked in a Nation-State Contest, Says NCSC CEO Webinar | The Future of SASE: Top 5 Predictions and Trends The Gentlemen Ransomware Gang Standardizes EDR Killing CISA Urges OT Resilience in Dark Remarks About Cyberattacks Attackers Steal Salesforce Data From Klue Battlecards Users Crime Gang Sells Access to 74,000 Fortinet Firewall Devices JPMorgan Pulls Anthropic Claude Access in Hong Kong Webinar | From SBOM to Submission: Operationalizing CRA Vulnerability Handling 6 Ways to Contain Enterprise Risk in Model Context Protocol Breach Roundup: ShinyHunters Leaks 26M MSG Records AI Inherits People Accenture Buys Majority Stake in Dragos in $4.2B Deal Multimillion-Dollar Settlement Reached in MCNA Dental Hack Addressing Quantum Readiness in Healthcare Security Experts Warn of Klue Confirms OAuth Token Theft Led to Salesforce Data Heist Cybercrime Initial Access Service SocGholish Disrupted From Reflection to Shadow: AI, Us and the Space in Between France and Germany Boost Digital Sovereignty Push ISMG Editors: Cyber Backlash Over the US Ban on Anthropic AI North Korean IT Workers Try, Try, Try Again HIPAA Europe Seeks to Advance 6G Security, Privacy No Zero-Day Tied to 80,000 Harvested Fortinet Credentials Sakana AI Bets on Agent Orchestration Over Frontier Models OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Is It Time to Put Some Teeth in Post-Quantum Guidelines? New AI Model Aims to Transform Behavioral Health AryStinger Botnet Converts Legacy Routers to Global Proxies Trump Executive Order Accelerates Post-Quantum Security Push North Korean Hackers Poison Mastra AI Framework
Aryon Secures $29M to Thwart Cloud Risks Before Deployment
Michael Novinson · 2026-06-25 · via DataBreachToday.com RSS Syndication
Series A Funds Back Enforcement Controls That Block Insecure Resources Instantly (MichaelNovinson) • June 24, 2026    
Aryon Secures $29M to Thwart Cloud Risks Before Deployment
Ariel Litmanovich, co-founder and CTO, Aryon Security (Image: Aryon Security)

A cloud security enforcement startup led by the ex-COO of Cyberillium raised $29 million to prevent cloud security risks during deployment rather than detecting them afterward.

See Also: Beat the Breach: Outsmart Attackers and Secure the Cloud

The Brightmind Partners-led Series A funding round will help Tel Aviv, Israel-based Aryon Security enforce security policies at the point where resources are being created or modified, said co-founder and chief technology officer Ariel Litmanovich. If a user tries to deploy a publicly exposed storage bucket, an unencrypted database or another insecure resource, Aryon's controls stop the deployment.

"The only way to make sure that your cloud environment is protected is by preventing those issues from ever reaching the cloud environment, and this is exactly what we do at Aryon," Litmanovich told ISMG. "We help organizations not detect but prevent cloud security risks at deployment, and by doing so, we dramatically reduce the risk and save a lot of time and effort and resources."

Aryon Security, founded in 2024, employs 54 people and has been led since its inception by Ron Arbel, who last spent nearly three years overseeing operations at Israeli security testing firm Cyberillium. Prior to that, Arbel spent nearly seven years in the Israeli Defense Forces, culminating in an 18-month stint as a hardware-oriented R&D team lead.

Why CNAPP, CSPM Aren't Suitable Against Today's Threats

Firms have spent years relying on CNAPP and CSPM tools to scan environments, spot misconfigurations and generate alerts, and Litmanovich said this approach requires security teams to investigate and remediate issues after they have already entered production environments. As cloud infrastructure becomes more complex and attackers move faster, this model is increasingly unsustainable, he said.

"The industry tried in the last few years the approach of detecting issues, remediating issues," Litmanovich said. "Now it becomes just harder and louder with more issues, and with the artificial intelligence era, it's even too late until you detect and remediate issues. So, now we feel that the market is ready for this preventative approach."

Cloud providers historically lacked enforcement mechanisms and controls, but over time, he said AWS, Microsoft Azure and Google Cloud have introduced more mature native capabilities that can be used to enforce security requirements safely and consistently. Organizations are increasingly recognizing that preventing risks before deployment is more effective than trying to manage an endless stream of alerts.

"Now it's possible to help medium and large enterprises from highly regulated industries," Litmanovich said. "We have customers from all those industries that actually make prevention and enforcement something that is actionable and works without any risk to break anything."

Aryon is focused on eliminating the conditions that often make attacks possible by preventing insecure resources, excessive permissions, weak configurations and other common mistakes, Litmanovich said. Insecure configurations are one of the leading contributors to successful cyberattacks, and he contends that preventing those mistakes offers a highly effective way to improve overall security posture.

"We are talking about operational prevention, not runtime prevention," Litmanovich said. "We don't prevent attackers. We prevent the creation or modification of insecure resources or identities. We want to help organizations make sure that those mistakes that are one of the leading causes of cybersecurity attacks are prevented by design."

Applying Aryon's Philosophy Beyond the Cloud

Although organizations may deploy resources through infrastructure-as-code tools, management consoles, command-line interfaces or automation frameworks, these methods ultimately interact with the same cloud APIs, Litmanovich said. This consistency allows Aryon to build enforcement controls that operate across multiple deployment methods and cloud services, Litmanovich said.

"Although the complexity of cloud environments is really huge and you have different ways to upload resources to the cloud, all those ways behind the scenes use the same APIs," Litmanovich said. "Aryon enables organization to enforce rules on those same APIs using behind the scenes cloud-native mechanisms."

The philosophy used in cloud environments can eventually be applied to SaaS applications, identity systems and even on-premises environments to better translate security policies into enforceable controls across their entire technology stack. Applying prevention to SaaS platforms such as Microsoft 365 can prevent files from being shared externally or require encryption settings to remain enabled.

"Aryon started with the cloud security use case, and this is the first use case of things that I want to prevent and not detect, but actually if we look at the market, there are more areas in which the preventative approach makes sense," he said. "We want to take this approach and expand it even beyond the cloud, and actually be the place in which CISOs and organizations can take their security."

Security enforcement introduces organizational challenges since legitimate business needs sometimes require exceptions to standard policies, so Aryon built workflows that help organizations understand violations, obtain approvals when necessary and implement controls without disrupting operations. The company offers feedback to users so they understand why a deployment was blocked and how to fix it.

"If someone does a mistake and tries to create an insecure resource or a publicly exposed storage or database, we prevent it at the deployment," Litmanovich said. "We provide very clear feedback on how to create the resource securely from the beginning, and then the issue is prevented, and the resource is recreated immediately without any problem."