Cloud Security Podcast cover image

Cloud Security Podcast

Latest episodes

undefined
Nov 14, 2021 • 38min

Challenges with Building Serverless Applications at Scale

In this episode of the Virtual Coffee with Ashish edition, we spoke with Ran Ribenzaft (@ranrib) is an AWS Serverless Hero, Forbes under 30 and the  co-Founder of Epsagon (@Epsagon). Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan) Guest Twitter:  Ran Ribenzaft (@ranrib) Podcast Twitter - Cloud Security Podcast (@CloudSecPod) If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel: - Cloud Security News  - Cloud Security Academy
undefined
Nov 10, 2021 • 4min

Microsoft releases CSPM for AWS & More Linux Security Support on Azure

Cloud Security News this week 10 November 2021 Microsoft is extending its native cloud security posture management (CSPM) and workload protection capabilities to Amazon Web Services (AWS) - yes you heard that right! within a suite called Microsoft Defender for Cloud. This was previously know as Azure Security Center and Azure Defender At their annual conference Ignite 2021, their focus was enterprise cloud protection, specially multi cloud environments. Microsoft Defender for Cloud will now let organizations secure AWS and Azure environments from one place without depending on the AWS Security Hub. We will bring you the highlights from Ignite 2021 next week, you can check out the event virtually here For folks who have been waiting on better security services support for Linux on Microsoft Azure - they recently announced the expansion of  the Defender for Endpoint on Linux capabilities. Defender for Endpoint is a cloud-based product that includes vulnerability management and assessment, and endpoint detection and response (EDR) on Linux servers.  Are you wondering about Oracle Cloud and what they are upto? Oracle Cloud most recently trying to stand out amongst its competitors by broadening the range of built-in and add-on cybersecurity features in Oracle Cloud Infrastructure. Oracle said the new features are intended not only to simplify management but also to address the problem misconfiguration and user error. If you want to find out more - you can check out their new Oracle Cloud Infrastructure Web Application Firewall for Flexible Load Balancers, Oracle Cloud Infrastructure Vulnerability Scanning Service, Oracle Cloud Infrastructure Bastion and Oracle Cloud Infrastructure Certificates If you use Crowdstrike, this ones for you. The popular real-time detection and automated response software, Crowstrike is making some big moves in the Cloud Space, doubling down on zero trust.  The National Security Agency (NSA) and CISA have published the first of a four-part series, Security Guidance for 5G Cloud Infrastructures. Security Guidance for 5G Cloud Infrastructures – Part I: Prevent and Detect Lateral Movement. Read more here If you have been reading about Robinhood being hacked, this one wasn't a cloud security breach however a good old social engineering attack which if your interested to know more about, you can read here Episode Show Notes on Cloud Security Podcast Website. Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News  If you want to watch videos of this LIVE STREAMED episode and past episodes, check out: - Cloud Security Podcast: - Cloud Security Academy:
undefined
Nov 7, 2021 • 38min

Security Governance and Compliance in Serverless Applications

In this episode of the Virtual Coffee with Ashish edition, we spoke with Jon Zeolla (@jonzeolla ) is a Cloud Native Contributor, co-founder CTO of Seiso. Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan) Guest Twitter:  Jon Zeolla (@jonzeolla ) Podcast Twitter - Cloud Security Podcast (@CloudSecPod) If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel: - Cloud Security News  - Cloud Security Academy
undefined
Nov 3, 2021 • 3min

AWS Earns over 16billion this quarter + SEGA on Microsoft Azure - Cloud Security News

Cloud Security News this week 27 October 2021 In case you missed the quarterly earnings updates from last episode, I do encourage you to check it out to see how Google Cloud and Azure faired last Quarter. AWS came out still leading the pack $16.11 billion in the quarter, up almost 39% from a year ago. You can view the report here  Industry Tech giants including Google, Salesforce, Okta and Slack have announced the creation of a “vendor-neutral” security baseline for businesses called ‘Minimum Viable Secure Product’ (MVSP). Its a minimalistic security checklist for B2B software and business process outsourcing supplier designed  to eliminate overhead, complexity and confusion during the procurement and vendor security assessment process by establishing minimum acceptable security baselines. The intention is to increase clarity reduce the onboarding and sales cycle by weeks or even months. You can view the checklist here Remote code execution vulnerability was patched by Gitlab in April 2021 however researchers from Rapid 7 recently found that the exploitations were continuing to this day, with  only 21% of the instances fully patched against the issue. Gitlab strongly recommends updating to the latest version to remedy this. Read more about Rapid 7’s research here and Gitlab’s release here IBM has released their report - Cloud’s Next Leap. They surveyed over 7000 executives in enterprise cloud adoption over 44 countries. 59% of organizations reported that digital transformation has accelerated for them through the pandemic. Not dissimilar to other reports this year, most of their respondents are also yet to fully realize cloud’s full transformational power. Hybrid cloud/multicloud once again is reported to be  the dominant architecture for cloud service delivery. Something rather interesting they reported on is that while many organisations are moving to the cloud, they are often moving to different versions of it.Report here For our sonic hedgehog gaming fans, Tokyo-based Sega is looking to produce large-scale, global games in a next-generation development environment built on Microsoft’s Azure cloud platform. The intent is to create big-budget titles using Microsoft’s know how  - who also own  Xbox cloud gaming tech. Episode Show Notes on Cloud Security Podcast Website. Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News  If you want to watch videos of this LIVE STREAMED episode and past episodes, check out: - Cloud Security Podcast: - Cloud Security Academy:
undefined
Oct 31, 2021 • 42min

How to Build Applications with Zero Trust Principles

In this episode of the Virtual Coffee with Ashish edition, we spoke with Maximilian Burkhardt (@maxb) is a Staff Security Engineer at Figma (@Figma) Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan) Guest Twitter:  Maximilian Burkhardt (@maxb) Podcast Twitter - Cloud Security Podcast (@CloudSecPod) If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel: - Cloud Security Podcast - www.cloudsecuritypodcast.tv - Cloud Security News  - Cloud Security Academy
undefined
Oct 28, 2021 • 21min

What is SaaS Security Posture Management (SSPM)?

In this episode of the Virtual Coffee with Ashish edition, we spoke with Chris Hughes (@Linkedin-Profile) is a host of the Resilient Cyber Podcast. Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan) Guest Twitter:  Chris Hughes (@Linkedin-Profile) Podcast Twitter - Cloud Security Podcast (@CloudSecPod) If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel: - Cloud Security Podcast - Cloud Security News  - Cloud Security Academy
undefined
Oct 27, 2021 • 6min

AWS Lands UK Spy Services Contact + Google Cloud + Azure release Q3 results - Cloud Security News

Cloud Security News this week 27 October 2021 UK’s spy agencies have given a contract to AWS to host classified material. Their intention is to boost use of data analytics and artificial intelligence for espionage. The agreement, estimated by industry experts to be worth £500m to £1bn over the next decade. The Guardian has reported that “the contract with Amazon is likely to ignite concerns over sovereignty because the UK’s most secret data will be hosted by a single US tech company” - Quite the interesting comment and Cloud Security News would love to hear your thoughts on this It's also the season for Revenue announcements for Quarter 3 for our big cloud providers. Google announced this week that Google Cloud revenue jumped 45 percent to $4.99 billion in the third quarter compared to the same period last year. You can view the results here Microsoft also announced their Quarter 3 revenue for Intelligent Cloud  to be $17.0 billion, an increase of   31% -  You can view the results here Microsoft shared earlier this month that things remain “Business as usual for Azure customers despite 2.4 Tbps DDoS attack” in Europe. They reported that the attack traffic originated from approximately 70,000 sources and from multiple countries in the Asia-Pacific region. Read the full statement from Microsoft here The Microsoft Threat Intelligence Center (MSTIC) has detected nation-state activity associated with NOBELIUM. It's quite the interesting read and the full blog can be found here. If you use discourse, a popular open source forum software, you should make sure that you update to Discourse versions 2.7.9 or later, as a security bug has been found that affects Discourse versions 2.7.8 and earlier. Read the Discord blog here Episode Show Notes on Cloud Security Podcast Website. Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News  If you want to watch videos of this LIVE STREAMED episode and past episodes, check out: - Cloud Security Podcast: - Cloud Security Academy:
undefined
Oct 24, 2021 • 47min

Threat Detection and Incident Response in Cloud - Nathan Case

In this episode of the Virtual Coffee with Ashish edition, we spoke with Nathan Case ( Linkedin Profile ) is a Senior Director, Security Operations at Resilience. Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan) Guest Twitter:  Nathan Case ( Linkedin Profile ) Podcast Twitter - Cloud Security Podcast (@CloudSecPod) If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel: - Cloud Security Podcast - Cloud Security News  - Cloud Security Academy
undefined
Oct 22, 2021 • 3min

HashiConf Global 2021 - Our Cloud Security Picks - Cloud Security News

Cloud Security News this week 22 October 2021 Hope you have been enjoying your Cloud Security News this week and in our special third instalment for this week we bring you our best bits from Hashiconf Global 2021, conference held by Hashicorp. Hashicorp is a software company who provide open source tools and products - some of their popular products Vagrant, Terraform, Vault and boundary - You can view the conference and the talks here The opening keynote was delivered by their Co-Founders Mitchell Hashimoto, Armon Dadgar, and CEO Dave McJannet - with key themes around Zero Trust, Hybrid and MultiCloud - looking to make Zero Trust more accessible for users. Mitchell Hashimoto spoke about the challenges Developers face when deploying applications with Kubernetes  and how Waypoint assists with this. They also spoke about the Hashicorp Cloud Platform (HCP) and the packer service which is now in public Beta, available free to use. Some of the features highlighted included remediation, enforcing security checks and maintaining images Shane Petrich from Target in his talk “Managing Target's Secrets Platform” spoke about how Target manages and maintains its enterprise deployment of HashiCorp Vault (Hashicorp’s secret management and data protection product) -- everything from unattended builds, automated maintenance activities, and client onboardings. Identity and account access is one of the first things you set up in the cloud and Austin Burdine, Mike Saraf and Yates Spearman share how Red Ventures implemented a custom Terraform solution to automate access management, meeting the requirements of various compliance frameworks Last year Hashicorp announced Boundary, their secure remote access solution. This year at Hashiconf 2021, Susmitha Girumala and Mike Gaffney from  HashiCorp showcased what is new in Boundary with a demo of key capabilities of identity-based access, integrated secrets management with Vault and dynamic host catalogs. Mark Guan and Ruoran Wang from Stripe’s Service Networking Team spoke about their multi-region service networking tech stack built on Consul (Hashicorp’s service networking solution), how it works across AWS accounts and regions, federated multi-region clusters and on Kubernetes. They also generously shared the challenges they faced. Episode Show Notes on Cloud Security Podcast Website. Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News  If you want to watch videos of this LIVE STREAMED episode and past episodes, check out: - Cloud Security Podcast: - Cloud Security Academy:
undefined
Oct 21, 2021 • 3min

Talks not to be missed at Kubecon North America 2021 - Cloud Security News

Cloud Security News this week 21 October 2021 It's a month full of conferences and as promised we are back with our 2nd episode this week to bring you the cloud security highlights from KubeCon. In this episode we will share some of our team’s favourite from Kubecon 2021 North America If you aren't quite familiar with the wonderful world of Kubernetes, there are a few weird and wonderful open source acronyms in today’s episode. TUF refers to The Update Framework, SPIFFE refers to Secure Production Identity Framework for Everyone SPIFFE,  SPIRE  is the SPIFFE’s Runtime Environment). Now that we are all across cool Kube words - lets into the talks Starting off with the talk from Andrew Martin, Co-Founder of Control Plane and Author of Hacking Kubernetes and Kubernetes Threat Modelling. He spoke about Kubernetes Supply Chain Security - he showcased work to build a Kubernetes Software Factory with Tekton and Deep dived on signing and verification approaches to securely build software with  (TUF) SPIFFE, SPIRE and sigstore Ian Coldwater from Twilio; Brad Geesaman & Rory McCune from Aqua Security Duffie Cooley from Isovalent combined  forces to share with the community how they do security research or hacking Kubenetes clusters using a recently discovered Kubernetes CVE (Common Vulnerability and exposure) - Their talk was called Exploiting a Slightly Peculiar Volume Configuration with SIG-Honk Matt Jarvis from Synk shared what to do if your container has a huge number of Vulnerabilities - how to prioritise them and remediate them in his talk My Container Image has 500 Vulnerabilities, Now What?  Talking about containers and Vulnerability scanning If you want to know about how vulnerability scanners work, their blind spots and how to implement a practical risk based approach to remedy vulnerabilities that really matter to your organisation - check out Pushkar Joglekar’s Keeping Up with the CVEs: How to Find a Needle in a Haystack?  If you find yourself asking “How do I access my S3 bucket in AWS from my GCP cluster?” Brandon Lum & Mariusz Sabath, IBM may have the answer for you in their talk Untangling the Multi-Cloud Identity and Access Problem With SPIFFE Tornjak where they talk about a proposed shift in the perspective of workload identity from being “platform specific” to “organization wide” using SPIFFE/SPIRE and the new SPIFFE Tornjak project. Episode Show Notes on Cloud Security Podcast Website. Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News  If you want to watch videos of this LIVE STREAMED episode and past episodes, check out: - Cloud Security Podcast: - Cloud Security Academy:

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode