Cloud Security Podcast

Feds go "Cloud Smart"+ Alibaba Cloud targeted by Hackers


Listen Later

Cloud Security News this week 17 November 2021

  • According to a research by Trend Micro, Elastic Computing Service (ECS) instances for Alibab Cloud are becoming an increasingly common target for financially motivated hackers with cryptomining goals. This increased targeting may be due to a few unique features of Alibaba Cloud. Alibaba ECS instances come with a preinstalled security agent and provides root access/ privileged control by default. There is a detailed article attached about this here
  • JupiterOne (a Cyber Asset Management Platform ) and Cisco have announced  the launch of Secure Cloud Insights, an expanded cloud security and security operations partnership designed to provide businesses with a range of cybersecurity services. This new solution is aimed at  helping Cisco customers achieve a higher level of maturity with their digital transformation and security program. CEO of Jupiter One, Erkang Zheng calls it a game changing offering - that would provide increased visibility, efficiency, and speed to security operations, with combined context from situational awareness and structural data. We would be curious to know if you think the same.
  • Those familiar with Palo Alto and their core cloud-security package, Prisma may be intrigued to know that they have launched Prisma 3.0. 
  • Truffle Security has released an open source hacking tools called Driftwood designed to discover leaked, paired private and public keys which may be harmful. Driftwood builds upon Truffle Hog and is available on Github. Truffle Security in their blog which is shared here. stated that With this tool they found the private keys for hundreds of Transport Layer Security certificates, and Secure Shell keys that would have allowed an attacker to compromise millions of endpoints/devices.
  • The Federal government is going from a  “Cloud First” to a “Cloud Smart” strategy to leverage cloud without compromising security. They quoted that “Cloud Smart is about equipping agencies with the tools and knowledge they need to make these decisions for themselves, rather than a one-size-fits-all approach.The shift will be from “buy before build” to “solve before buy,”. Under security they added that “Successfully managing cloud adoption risks requires collaboration” leaning into that shared responsibility model we hear often about with Cloud Security. The link to the document is here
  • Episode Show Notes on Cloud Security Podcast Website.

    Podcast Twitter - Cloud Security Podcast (@CloudSecPod)

    Instagram - Cloud Security News 

    If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:

    - Cloud Security Podcast:

    - Cloud Security Academy:

    ...more
    View all episodesView all episodes
    Download on the App Store

    Cloud Security PodcastBy Cloud Security Podcast Team

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    54 ratings


    More shows like Cloud Security Podcast

    View all
    Risky Business by Patrick Gray

    Risky Business

    360 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    628 Listeners

    The Cloudcast by Massive Studios

    The Cloudcast

    153 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    368 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,012 Listeners

    AWS Podcast by Amazon Web Services

    AWS Podcast

    201 Listeners

    Smashing Security by Graham Cluley & Carole Theriault

    Smashing Security

    313 Listeners

    Malicious Life by Malicious Life

    Malicious Life

    926 Listeners

    Darknet Diaries by Jack Rhysider

    Darknet Diaries

    7,842 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    164 Listeners

    CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

    CISO Series Podcast

    187 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    311 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    78 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    119 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    33 Listeners