

Crying Out Cloud
Wiz
Welcome to "Crying Out Cloud," the monthly podcast that keeps you up to date with the latest cloud security news. Hosted by experts Eden Naftali and Amitai Cohen, each episode provides in-depth coverage of the most important vulnerabilities and incidents from the previous month. Tune in for insightful analysis and expert recommendations to help you safeguard your cloud infrastructure.
Episodes
Mentioned books

May 8, 2025 • 40min
Bug Bounty Secrets, Hacker Communities, and a Hit of Volleyball with Justin Gardner
🎙️ Listen to the biggest insights of bug bounty hunting with Justin Gardner 🚨In this episode, Amitai Cohen and Eden Naftali are joined by none other than Justin, renowned bug bounty hunter and host of the Creative Thinking podcast (ctbbpodcast).Justin unpacks some of today's 🔥 topics:- Bug bounty disclosure challenges & trends- Security stories from tech giants: lessons we can all learn- Messaging platform exploits & SSRF risks- Breaking into popular monitoring tools — HTTP pitfalls & key takeaways

Apr 9, 2025 • 29min
Quadruple Supply Chain Attack, IngressNightmare Exploited, and Rumors Abound
🎙️ All you need to know on the latest discoveries and updates ft. Rami McCarthy 🚨In this episode of Crying Out Cloud, @Amitai Cohen & @Eden Koby Naftali are joined by Rami — a Principal Security Researcher here at Wiz.Rami adds some energy and expertise to the table as we dive into a variety of topics:• GitHub Action supply chain attack • IngressNightmare updates. A follow-up to our last episode on this critical vulnerability.• Alleged Oracle breaches: Breaking down the latest rumors and insights.

Mar 25, 2025 • 22min
Ingress Nightmare: How a Single Request Could Take Over Your K8s Cluster
🎙️ All you need to know on our latest discovery #IngressNightmare 🚨In this episode of Crying Out Cloud, Amitai Cohen & Eden Koby Naftali are joined by Nir Ohfeld — Head of Vulnerability Research at Wiz. Nir and his team have uncovered some of the most impactful vulnerabilities affecting cloud and SaaS applications. In this episode, he's diving into the latest discovery, a critical vulnerability in Ingress-NGINX:• How the team uncovered a critical unauthenticated RCE in NGINX Ingress Controller• Why Kubernetes admission controllers might be the next big attack surface• The wild journey of hunting vulnerabilities in the cloud

Mar 5, 2025 • 22min
From Hotmail Hacks to AI hype, CTFs & Cloud Guardian: with Ashish Rajan
🎙 Ready for the latest on AI, cloud security, and Fortune 500 challenges?This week on our podcast Crying Out Cloud, we're joined by none other than Ashish Rajan— a seasoned cybersecurity leader and host of the AI Cybersecurity Podcast & Cloud Security Podcast.Amitai Cohen & Eden Koby Naftali dive into:- The evolution of AI & cloud security- Lessons from securing Fortune 500 & FTSE 100 companies- The biggest challenges (and laughs) in the industry

Feb 21, 2025 • 23min
HACKERS ARE HIJACKING CLOUD KEYS: The Rise of Cloud-Native Ransomware
From Supply Chain Attacks to S3 Ransomware: Critical Cloud Security Stories You Need to Know.🎙️ In this episode of Crying Out Cloud, Eden and Amitai break down the latest cloud security chaos, from sneaky supply chain attacks to AI-powered malware:1) How attackers exploited a GitHub misconfiguration to enable a supply chain attack.2) The latest twist on cloud-native extortion (spoiler: it all comes back to stolen cloud keys).3) NullifAI – Malicious AI models hiding in plain sight.4) whoAMI attack – The clever AWS AMI name confusion flaw that might catch you off guard.

Feb 10, 2025 • 22min
Norwegian Cloud Security, Open Source Tools, and Financial Sector Risks with Karim El-Melhaoui
🎙️ SEASON PREMIERE ALERT: Tune in to our latest episode featuring Karim El-Melhaoui, where we dive into the latest cloud security challenges ☁️🔥 Amitai Cohen & Eden Koby Naftali are kicking off the season with:- Cyber risk vs. operational risk – Why cyber risk is harder to quantify and how Norges Bank used NIST's Cybersecurity Framework to strengthen resilience.- Open-source tools fuel innovation, but many are abandoned without long-term support.- How cloud security alliance Norway is setting stronger security standards.🎧 Ready for season 3 of #CryingOutCloud?

Jan 30, 2025 • 11min
DeepSeek Data Leak with Gal Nagli (Wiz Research)
Why is everyone suddenly talking about DeepSeek? 👀
🎙️ If you've been seeing DeepSeek everywhere but are wondering what the actual buzz is about - this is for you: Our new podcast features Gal Nagli from the Wiz Research team, breaking it down with Eden Koby Naftali and Amitai Cohen.
Plus: Get the full story behind our recent DeepSeek database discovery that made headlines ⚡

Dec 23, 2024 • 32min
Co-Founding Wiz, R&D and Security Leadership with Roy Reznik
Roy Reznik, Co-founder and VP of R&D at Wiz, shares his fascinating journey from Tel Aviv to London and the cultural shifts within startup dynamics. He emphasizes the importance of embedding security into development practices and fostering a proactive culture among developers. The conversation also explores innovative security strategies at Wiz, alongside insights on the evolving role of AI in development teams. Interwoven are amusing anecdotes, including a playful dog encounter and spirited basketball debates, adding depth to his tech saga.

Dec 13, 2024 • 33min
post:Invent with Scott Piper (re:Invent digest)
🎙️ Unpack AWS re:Invent's top announcements, trends, and what's next for cloud practitioners with @Scott Piper!
Join Eden Naftali and Amitai Cohen in our latest #CryingOutCloud episode featuring Scott Piper, Wiz's Principal Cloud Security Researcher and "cloud security historian".
In this episode:
🌟 AWS re:Invent highlights: Aurora DSQL, Nova genAI, EKS Auto Mode
🔒 Security updates on RCPs, VPC Block Public Access, Declarative Policies for EC2
🎬 Scott's favorite cloud-themed movies from Wiz Video World (Pulp Encryption, anyone?)

4 snips
Nov 29, 2024 • 35min
Red Team Tactics with EA’s Johann Rehberger
Join Johann Rehberger, Red Team Director at Electronic Arts and cybersecurity expert, as he shares his unique journey from database enthusiast to security innovator. He dives into red teaming strategies and the importance of ethical hacking in today’s AI landscape. Johann also reveals insights from his cutting-edge research and discusses the vulnerabilities in AI systems, including Unicode exploitation. Plus, he shares a funny anecdote about his alias, Wunderwuzzi, adding a personal touch to this tech-savvy conversation.


