#cnapp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cnapp, aggregated by home.social.
-
Kubernetes-аудит после Wiz и Prisma: как живут без CNAPP в 2026
В 2022–2024 западные CNAPP-платформы — Wiz, Prisma Cloud, Lacework — закрыли доступ для российских компаний. Сбер и Яндекс собрали свой стек на коленке, а вот у банков второго эшелона и финтеха с командой ИБ из 1-3 человек стало больно: Kubernetes в проде, аудит ФСТЭК через три месяца, а показать аудитору нечего. С 1 марта 2026 действует Приказ ФСТЭК №117, где контейнеризация впервые выделена в отдельную группу мер защиты. Рассказываю, как сейчас выглядит K8s-аудит без Wiz, что предлагают Kaspersky Container Security и НОТА КУПОЛ, и показываю OSS-инструмент, который пишу под эту задачу. Читать далееЧто показывать аудитору
https://habr.com/ru/articles/1039100/
#kubernetes #security #devsecops #фстэк #compliance #cnapp #container_security #приказ_117 #аудит #k8s
-
Near-realtime-защита внутри облака: как мы боролись с лавиной ИБ-событий и превращали их в полезные данные
Меня зовут Владислав Архипов, я архитектор команды разработки security‑сервисов в Yandex Cloud. Мы занимаемся как непосредственной безопасностью облачной платформы и её клиентов, так и созданием сервисов безопасности. Итоги 2025 года в сфере информационной безопасности показали, что нагрузка на security‑команды любого уровня растёт вместе с ростом потока данных. На нашем примере: к середине 2025 года количество типовых событий безопасности, которые мы обрабатывали, в среднем составляло 28 млрд в день, а рост за год составил 20%. При этом всё чаще необходимо анализировать потоковые источники данных, где традиционные подходы с периодической выгрузкой информации просто исчерпали себя. В этой статье вместе с руководителем Cloud Security Operations Юрием Наместниковым @namestnikov мы расскажем, как создаём Security Deck и добиваемся прозрачности процессов ИБ, а также о том, как хронологическое хранилище помогает справляться с растущими потоками данных. Покажем, как мы превращаем разрозненные события в стейт и храним в хронологической базе данных, а также в чём отличие нашего запатентованного решения от других на уровне архитектуры.
https://habr.com/ru/companies/yandex_cloud_and_infra/articles/994478/
#безопасность #хронологическое_хранилище #temporal_bd #ydb #security_operation_center #soc #cspm #cnapp
-
New IDC research highlights a major cloud security shift - https://www.redpacketsecurity.com/new-idc-research-highlights-a-major-cloud-security-shift/
#threatintel
#cloud security
#CNAPP
#SecOps
#Generative AI
#cloud-native security -
Cloud compliance dashboards, CNAPP, and CSPM can all show green, but they don't show your entire attack surface.
The issue is not with the dashboards, but with the blind spots that lie outside their view, such as leaked developer personal access tokens or overprivileged pipelines that do not appear as non-compliant.
In this blog post, Joe Durbin looks at those gaps around tokens, pipelines, and third-party build services. He explains how human-led configuration reviews and custom threat actor simulations work alongside provider tools to show and test your actual attack surface.
📌https://www.pentestpartners.com/security-blog/beyond-cloud-compliance-dashboards-whats-next/
#cloudsecurity #cloudnative #devsecops #cnapp #cspm #cybersecurity
-
Akamai Extends Cybersecurity Reach to DNS Posture Management – Source: securityboulevard.com https://ciso2ciso.com/akamai-extends-cybersecurity-reach-to-dns-posture-management-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #CyberSecurityNews #posturemanagement #SecurityBoulevard #Cybersecurity #Spotlight #FEATURED #SocialX #Akamai #cnapp #DNS
-
Check Point, Wiz Partner on Enterprise Cloud Security – Source: securityboulevard.com https://ciso2ciso.com/check-point-wiz-partner-on-enterprise-cloud-security-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #CyberSecurityNews #SecurityBoulevard #SocialFacebook #SocialLinkedIn #CloudSecurity #Cybersecurity #CheckPoint #Spotlight #FEATURED #SocialX #cloud #cnapp #News #Wiz
-
Orca Security Adds Additional CNAPP Deployment Options – Source: securityboulevard.com https://ciso2ciso.com/orca-security-adds-additional-cnapp-deployment-options-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #CyberSecurityNews #SecurityBoulevard #cloudcomputing #SocialFacebook #SocialLinkedIn #CloudSecurity #Cybersecurity #OrcaSecurity #Spotlight #FEATURED #SocialX #cnapp #SaaS
-
От CNAPP до CTEM — ИБ-термины простыми словами
Современные облачные сервисы и другие области ИТ включают большое количество специализированных терминов и аббревиатур, связанных с информационной безопасностью. Чтобы упростить понимание этих понятий, мы подготовили компактный словарь для менеджеров и начинающих специалистов. Простыми словами объясняем распространённые термины, обозначающие механизмы и решения для защиты различных сред: от управления правами доступа до межсетевых экранов. Материал поможет разобраться в технологиях безопасности и сделать их использование максимально эффективным.
-
Exabeam Allies With Wiz to Integrate CNAPP With SIEM Platform – Source: securityboulevard.com https://ciso2ciso.com/exabeam-allies-with-wiz-to-integrate-cnapp-with-siem-platform-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #ApplicationSecurity #CyberSecurityNews #SecurityBoulevard #SocialFacebook #SocialLinkedIn #Cybersecurity #FEATURED #SocialX #cnapp #News #SIEM
-
Fortinet Expands Cloud Security Portfolio with Lacework Acquisition https://www.securityweek.com/fortinet-expands-cloud-security-portfolio-with-lacework-acquisition/ #CloudSecurity #Funding/M&A #M&ATracker #Featured #Fortinet #Lacework #CNAPP #DSPM
-
Fortinet Expands Cloud Security Portfolio with Lacework Acquisition https://www.securityweek.com/fortinet-expands-cloud-security-portfolio-with-lacework-acquisition/ #CloudSecurity #Funding/M&A #M&ATracker #Featured #Fortinet #Lacework #CNAPP #DSPM
-
PRISMA CLOUD – Source: securityboulevard.com https://ciso2ciso.com/prisma-cloud-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #cnapp
-
Wiz – Source: securityboulevard.com https://ciso2ciso.com/wiz-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #CyberSecurityNews #SecurityBoulevard #cnapp
-
#Ouch 🤯
Cyber decacorn Wiz in advanced negotiation to acquire Lacework for $150-200 million
Lacework was valued at $8.3 billion in 2021
#cybersecurity #cybersec #cloudsecurity #cnapp #consolidation
-
Yeesh, how fast things shift in startup land. Just a reminder that it's all funny money until it's in your bank account.
Lacework was an early leader in the cloud security market and had a whopping $8 BILLION valuation just a few years ago. Wiz is mopping the floor in that market now due to their simple deployment and time-to-value. Spending $200M to acquire $100M in ARR and also remove one of your direct competitors seems like a great deal for them.
-
Reconsider Your CNAPP Strategy Using These 5 Scenarios – Source: www.darkreading.com https://ciso2ciso.com/reconsider-your-cnapp-strategy-using-these-5-scenarios-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #cnapp
-
𝐌𝐚𝐩 𝐂𝐨𝐧𝐭𝐚𝐢𝐧𝐞𝐫 𝐈𝐦𝐚𝐠𝐞𝐬 𝐟𝐫𝐨𝐦 𝐂𝐨𝐝𝐞 𝐭𝐨 𝐂𝐥𝐨𝐮𝐝 𝐰𝐢𝐭𝐡 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐟𝐨𝐫 𝐂𝐥𝐨𝐮𝐝
When a vulnerability is identified in a container image stored in a container registry or running in a Kubernetes cluster, it can be difficult for a security practitioner to trace back to the CI/CD pipeline that first built the container image and identify a developer remediation owner.
With DevOps security capabilities in Microsoft Defender Cloud Security Posture Management (CSPM), you can map your cloud-native applications from code to cloud to easily kick off developer remediation workflows and reduce the time to remediation of vulnerabilities in your container images.
Details: https://learn.microsoft.com/en-us/azure/defender-for-cloud/container-image-mapping
#defender #cspm #CloudSecurityPostureManagement #devops #pipeline #codetocloud #container #vulnerabilities #Kubernetes #cnapp #cwpp #cloudnative #cloudsecurity #soc #microsoft #microsoftsecurity #azure #multicoud
-
#Dynatrace Unlocks AI-Driven Compliance & Protection With #Runecast Acquisition
-
𝐈𝐧𝐭𝐫𝐨𝐝𝐮𝐜𝐢𝐧𝐠 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫 𝐟𝐨𝐫 𝐂𝐥𝐨𝐮𝐝 𝐋𝐚𝐛𝐬
Our labs project help you get ramped up with Microsoft Defender for Cloud and provide hands-on practical experience for product features, capabilities, and scenarios. The labs are divided into 3 main tracks, a beginner (level 100/200) and an advanced (level 300+) track. The labs contain several modules cover different pillars such as Cloud Security Posture Management (CSPM) to Cloud Workload Protection (CWP). To start using our labs, you will need to create Azure Trial Subscription which provides you all capabilities for 30 days – so you have to finish this lab at this point to take advantage of the free trial.
https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Labs
#defender #defenderforcloud #cnapp #cspm #cwp #cwpp #cloudsecurity #multicloud #azure #aws #gcp #microsoft #microsoftsecurity #soc #server #container #storage #dns #api #devops #database #api #github #arc #agentless #storageaccount #mde #vulnerability #mdvm #siem
-
𝐍𝐞𝐰 𝐮𝐬𝐞 𝐜𝐚𝐬𝐞𝐬 𝐟𝐨𝐫 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐩𝐢𝐥𝐨𝐭
📣 The new use cases for Security Copilot now extend beyond investigations in your security operations center to support various security necessities for organizations seeking to strengthen their security against cyberthreats.
➡Device management
➡Identity management
➡Data security
➡Cloud security
➡External attack surface management
📣Security Copilot is expanding into embedded experiences across various Microsoft Security solutions!
#copilot #security #securitycopilot #llm #ai #genai #openai #microsoft #microsoftsecurity #cybersecurity #intune #purview #entraid #soc #xdr #siem #soar #cloud #cloudnative #cloudsecurity #sentinel #microsoftsentinel #cnapp #defenderforcloud #defender #easm #threatintelligence
-
𝐍𝐞𝐰 𝐮𝐬𝐞 𝐜𝐚𝐬𝐞𝐬 𝐟𝐨𝐫 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐩𝐢𝐥𝐨𝐭
📣 The new use cases for Security Copilot now extend beyond investigations in your security operations center to support various security necessities for organizations seeking to strengthen their security against cyberthreats.
➡Device management
➡Identity management
➡Data security
➡Cloud security
➡External attack surface management
📣Security Copilot is expanding into embedded experiences across various Microsoft Security solutions!
#copilot #security #securitycopilot #llm #ai #genai #openai #microsoft #microsoftsecurity #cybersecurity #intune #purview #entraid #soc #xdr #siem #soar #cloud #cloudnative #cloudsecurity #sentinel #microsoftsentinel #cnapp #defenderforcloud #defender #easm #threatintelligence
-
Prepare to onboard Microsoft Defender for Cloud (MDC) with Terraform: The new Terraform module, "mdc-defender-plans-azure" allows you to configure MDC plans for your subscriptions or management groups with just a few lines of code!
"Simplifying Onboarding to Microsoft Defender for Cloud with Terraform" - Microsoft Community Hub
https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/simplifying-onboarding-to-microsoft-defender-for-cloud-with/ba-p/3974789#MicrosoftDefenderForCloud #DefenderCSPM #IaC #Terraform #CSPM #CNAPP #MDFC #Security #Cybersecurity #Microsoft #Azure
-
Earlier this year @baileybercik and I presented at SANS #Cloud #Security summit on what we've learned from the last 18 or so months of deploying #CIEM as part of that broader #CNAPP strategy. We focused mostly on #Microsoft #Entra Permissions Management. The talk is now posted, https://www.youtube.com/watch?v=q2pdf_8aorg. If you want to learn more about #CNAPP see this post, https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/announcing-new-cnapp-capabilities-in-defender-for-cloud/ba-p/3981941. We also recently released an operations guide which has been very helpful for customers. Give it a read. https://learn.microsoft.com/en-us/entra/architecture/permissions-manage-ops-guide-intro. #InfoSec #Azure #AWS #GCP
-
"#CNAPP is arguably superior because of its ability to integrate end-to-end cloud-native security[...] It provides a holistic approach to bringing cloud-native security and #DevOps practices together." –Gaurav Belani, #Security Boulevard
https://securityboulevard.com/2023/11/adopting-cnapp-as-a-bridge-between-devops-and-cloud-native-security -
𝗔𝗻𝗻𝗼𝘂𝗻𝗰𝗶𝗻𝗴 𝗻𝗲𝘄 𝗖𝗡𝗔𝗣𝗣 𝗰𝗮𝗽𝗮𝗯𝗶𝗹𝗶𝘁𝗶𝗲𝘀 𝗶𝗻 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗖𝗹𝗼𝘂𝗱
At Ignite 2023, we are excited to announce new innovations in Microsoft Defender for Cloud that will help security admins strengthen their CNAPP deployment, improve the cloud security posture through additional code to cloud insights, and protect cloud-native applications across multicloud environments in a unified solution:
➡ Unified insights from Microsoft Entra Permissions Management (CIEM) to enable comprehensive risk mitigation
➡Enhanced attack path analysis engine to swiftly pinpoint critical risks across clouds
➡Accelerated critical risk remediation with Microsoft Security Copilot integration
➡Integrated security across multiple DevOps platforms
Extended protection for cloud workloads
➡Improved API Security Posture
➡Go beyond workload protection – detect and respond to threats across the enterprise in a unified platform
More details:
#cnapp #devops #api #protection #ciem #cwp #cspm #defender #defenderforcloud #azure #gcp #aws #cloud #cloudnative #cloudprotection #cloudsecurity #multicloud #microsoft #microsoftsecurity #soc #ignite #microsoftignite #permissionmanagement #ai #mitre #copilot #securitycopilot #vulnerability
-
It's taken me almost a year to write (and edit) my rant about categories and acronyms in cybersecurity. Which acronyms or categories annoy you the most? Security teams don't need more tools, they need efficient ways to mitigate risk and respond quickly to threats or attacks - especially now to keep up with faster development cycles.
https://www.techtarget.com/searchsecurity/opinion/Cloud-native-app-security-Ignore-acronyms-solve-problems
#cloudsecurity #applicationsecurity #appsec #cspm #sast #dast #iast #sca #sbom #ciem #asoc #dspm #aspm #cnapp #cdr #mdr #itdr #ndr #mdr #xdr #edr #cnapp #wapp #devsecops #cybersecurity #infosec #ciso #cso