Cloud Security Podcast cover image

Cloud Security Podcast

Latest episodes

undefined
Nov 21, 2023 • 43min

Secure your SaaS applications like this!

SaaS Applications support large companies, small startups. We inevitably accumulate SAAS applications to manage our employees, payroll, communication with things like Workday, Slack, Salesforce and now even things like ChatGPT. But how do you find out what you have and if they are secure. We spoke about all things SSPM with Max Feldman who has done Product Security for years at companies like Slack, Salesforce and now AppOmni. Thank you to our episode sponsor AppOmni You can get a copy of their SaaS Security Posture Management Report 2023 here Guest Socials: Max's Linkedin ⁠(@maxfeldman14)⁠ Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels: - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp⁠ Questions asked: (00:00) Introduction (04:20) A bit about Max (04:48) What is a SaaS application? (05:45) What is SSPM? (09:33) When to consider a SSPM? (15:45) SaaS and the Cloud (16:39) SaaS Attack Surface (19:34) CASB vs SSPM (24:00) Is ChatGPT a SaaS application? (25:07) SSPM vs CSPM + CNAPP (27:33) SSO and Onboarding (29:21) Starting a SaaS Security Program (36:48) Challenges with SaaS Security Program (41:50) Where you can find Max!
undefined
5 snips
Nov 11, 2023 • 35min

Threat Detection for not so Common Cloud Services

Threat detection for not so common cloud services features Suresh Vasudevan, CEO of Sysdig, discussing challenges in threat detection for uncommon cloud services. They explore traditional threat detection methods, uncommon service attack vectors, and problems with threat detection in the cloud. The podcast also covers prioritization approaches and bridging cloud and applications.
undefined
10 snips
Nov 7, 2023 • 59min

How to Escape Clusters in a Managed Kubernetes Cluster?

Not Escaping Containers but escaping Clusters - Managed Kubernetes distributions such as Amazon EKS, Google Kubernetes Engine (GKE) and Azure Kubernetes Service (AKS) attack vectors can allow you to reach the underlying AWS Account etc. In conversation with Christophe Tafani-Dereeper & Nick Frichette, from Datadog on how this is possible in Amazon EKS and achieving potentially the same in GKE & AKS too. Thank you to our episode sponsor Sagetap Guest Socials: Nick's and Christophe's Linkedin (⁠⁠⁠⁠⁠⁠⁠⁠⁠Nick Frichette + Christophe Tafani-Dereeper) Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels: - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp Questions asked: (00:00) Introduction (04:11) A bit about Christophe (04:37) A bit about Nick (05:03) What is managed Kubernetes? (06:26) Security of managed Kubernetes (09:02) Comparison between different managed Kubernetes (10:41) Service accounts and managed Kubernetes (14:22) What is container escape? (18:20) IMDSv2 for EKS (19:51) IMDSv2 in EKS vs AKES and GKE (22:01) Benchmark compliance for Kubernetes architecture (24:49) Low hanging fruits for container escape (27:17) Shared responsibility for managed Kubernetes (29:34) Fargate for Managed Kubernetes (32:00) Different ways to run containers (33:37) Escaping Managed Kubernetes cluster (38:39) Find more about this attack path (42:38) Escalation priviledge in EKS cluster (44:19) Reducing the Kubernetes attack service (44:58) MKAT for Kubernetes Security (48:23) Preventing AWS AuthConfig (50:11) Propagation Security (54:55) The fun section (57:47) Resources for latest Kubernetes updates Resources spoken about during the episode Nick Frichette's Blog - Hacking the Cloud Christophe Tafani-Dereeper' Blog Corey Quinn's - 17 ways to run containers on AWS MKAT cloudseclist newsletter
undefined
Nov 6, 2023 • 29min

Have I lost my Secrets?

Ziad Ghalleb, Founder of GitGuardian, talks about their free tool 'HasMySecretLeaked' to check if your secret was exposed on GitHub. They discuss the perception of secrets and security among developers, the importance of addressing leaked secrets, and the need to avoid repeating mistakes. The podcast also explores challenges with shadow code and personal emails on GitHub and highlights resources for increasing awareness and ensuring secret security.
undefined
Nov 1, 2023 • 33min

How to become a Senior Cloud Security Engineer?

Nick McLaren, a Senior Cloud Security Engineer at an Enterprise, discusses the differences between working in a startup and an enterprise, the skills and mindset required to become a senior cloud security engineer, the importance of understanding cloud platforms and security tools, and perseverance and personal growth in the field.
undefined
Oct 7, 2023 • 16min

5 Skills to Level Up Your Cloud Hacking

Learn about the essential skills needed to excel as a Cloud Hacker in 2023, including identity, cloud infrastructure security, CI/CD security, preventative security, and data security. Gain insights from DEFCON 31 and discover the key focus areas for Red teamers. Discuss the challenges CSOs face in managing identity and access in cloud security. Explore the importance of data security skills for Cloud Hackers and the complexity of cloud security. Uncover the various skills crucial for a cloud hacker, including static analysis, infrastructure testing, and CI/CD security.
undefined
Oct 2, 2023 • 37min

Become a Cloud Native CISO in 2023

Michael Piacente, security executive recruiter for Lyft, Instacart, and Airbnb, discusses the rise of Cloud Native CISOs and the skills needed to succeed in this role. They explore different leadership roles in security, compensation for CISOs, protecting oneself in the role, changing responsibilities, and the importance of personal branding. Overall, it provides valuable insights for aspiring Cloud Native CISOs.
undefined
Sep 21, 2023 • 40min

Software Supply Chain Controls for Terraform

Understanding Software Supply Chain security threats for Terraform which has been the default for Infrastructure as Code is important. in this episode Mike Ruth is sharing his experience of working on securing Terraform Cloud/Terraform Enterprise - no open source was harmed in the making of this episode. Episode YouTube: ⁠⁠⁠ ⁠⁠⁠⁠⁠Video Link⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Host Twitter: Ashish Rajan (⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@hashishrajan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠) Guest Socials: Mike's Linkedin (⁠⁠Mike Ruth) Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels: - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Spotify TimeStamp for Interview Question (00:00) Introduction (03:27) A bit about Mike Ruth (04:01) What is Terraform? (05:38) Terraform in the context of supply chain (07:24) Flavors of Terraform (09:07) Deploying Terraform (12:25) Terraform Architecture (14:48) Research findings that Mike and Oca made (25:52) Securing Terraform Architecture (28:13) Policy Enforcement (29:13) What is a Module? (30:15) Security best practices for Terraform Deployment (31:53) Learning about Terraform security (34:44) Maturity for Terraform (37:45) The Fun Questions Mike spoke about Terraform Cloud Security Model during the interview. See you at the next episode!
undefined
Sep 18, 2023 • 17min

Data Security RoadMap in 2023

DSPM or Data Security Posture Management with Yotam Segev from Cyera: Most security teams have known about data challenges in their organization and some of them are put in the too hard to solve right now bucket. Yotam came on the show to talk about who should own and manage data security programs and what can a data security roadmap look like for leaders who are working on the data problem today. Episode YouTube: ⁠⁠⁠ ⁠⁠⁠⁠Video Link⁠⁠⁠⁠⁠⁠⁠⁠⁠ Host Twitter: Ashish Rajan (⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@hashishrajan⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠) Guest Socials: Yotam's Linkedin (⁠Yotam Segev⁠⁠) Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels: - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Spotify TimeStamp for Interview Question (00:00) Introduction (04:32) Why is data security getting attention? (05:46) How was data security done before? (06:43) Cloud native way of managing data (07:31) What triggers a data security project? (08:35) At what stage should you start data security? (10:06) Challenges with starting data security projects (13:02) What does success look like? (15:02) Does the CISO own data security? (16:03) The right skill set for data security See you at the next episode!
undefined
Sep 9, 2023 • 25min

The Cloud to Code Dilemma - Let's Talk

Harshil Parikh, CISO experience on code to cloud and cloud to code. What should CISOs prioritize? How different sectors are impacted. Application vs Cloud vs Product Security. Is application security becoming cloud security? What does maturity look like?

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode