

Crying Out Cloud
Wiz
Welcome to "Crying Out Cloud," the monthly podcast that keeps you up to date with the latest cloud security news. Hosted by experts Eden Naftali and Amitai Cohen, each episode provides in-depth coverage of the most important vulnerabilities and incidents from the previous month. Tune in for insightful analysis and expert recommendations to help you safeguard your cloud infrastructure.
Episodes
Mentioned books

Jun 6, 2024 • 39min
CROC Talks: Chief Llama Officer and IBM CISO - Jerry Bell
What is it like to be IBM's 'Chief Llama Officer'? 🦙
🎙️ Tune in as Jerry Bell shares his journey from crashing his first computer at 10 to leading IBM's Public Cloud Security
What's on today's agenda?
😲 Managing a popular 'Mastodon' server post-Twitter acquisition
🛡️ Challenges and surprises as IBM's CISO
🔐 Insights on the security implications of M&A

May 27, 2024 • 23min
CROC News: Ninjas, Grand Theft AI, and Backlogged CVEs
🎙️ All that's 🔥 in the cloud: From logging and cloud attacks to NVD backlog updates.
what's on today's agenda?
1️⃣ Discover how logging bypass made password-spray attacks undetectable.
2️⃣ Learn about the latest way attackers are monetizing cloud access - by selling access to other people's AI models.
3️⃣ NVD's ongoing backlog - Hear about how the industry is dealing with it.

May 9, 2024 • 34min
CROC Talks - Threat Models, Cloud Tools, and Security Tales - Special Guest: Kat Traxler
Our latest episode of Crying out cloud features none other than Kat Traxler, a seasoned security professional renowned for her expertise in cloud research.🚀
Here's a sneak peek at what we'll cover:
🔍 Threat modeling: Kat's practical insights
🔧 "DeRF": Kat's revolutionary tool and how it can help cloud security practitioners
💡 Dispelling myths about cloud security and how it challenges the OSI model
🔬 Future research directions in cloud security & Kat's latest projects in the field

Apr 4, 2024 • 11min
CROC Talks: Helping Secure Hugging Face Hub - Special Guest: Shir Tamari
🚨 BREAKING: Wiz Research identifies critical risks in #AI-as-a-service 🚨
Dive into Crying Out Cloud's latest episode, featuring a very special guest, Shir Tamari, head of the research team at Wiz. This episode sheds light on the security challenges that come with the rapid integration of AI technologies. Highlights include:
🚀 Exploring the rapid integration of AI and its associated security risks, identified by Wiz Research in collaboration with Hugging Face.
🛡️ Exposing two significant security flaws within Hugging Face's systems: shared inference and CI/CD systems, which could potentially offer unauthorized access to sensitive data.
📢 Highlighting the critical need for robust security frameworks in AI services.
✅ Demonstrating Hugging Face's dedication to security through the adoption of Wiz CSPM, continuous vulnerability assessments, and annual penetration tests, thereby establishing a high standard in AI safety.

Mar 31, 2024 • 13min
CROC News - XZ Utils backdoor explained
The backdoor in XZ Utils is shaking the industry 🔔
How could we not talk about it?
Tune in to the special unscheduled episode of Crying Out Cloud with Eden Naftali and Amitai Cohen as they delve into the stealthy supply chain attack!
In this episode:
🔍 The Alert from CISA regarding CVE-2024-3094, a vulnerability in XZ Utils Data Compression Library versions 5.6.0 and 5.6.1
🛑 The potential risks posed by the embedded malicious code and the unauthorized access it may grant to affected systems
🛡️ Security Team Action Plans
Tune in now!

Mar 26, 2024 • 32min
CROC News: Malicious Repos, Bandwidth Theft, & NVD or NoVD?
🎙️ What is a better way to stay updated on cloud security than a NEW Crying Out Cloud episode!
Join Eden Naftali and Amitai Cohen as they explore what is new and 🔥:
👾 Open-source repos flooded by malicious code.
💻 What is to become of the National Vulnerability Database?
⛓️ Proof of bandwidth cryptojacking
🛠️ Critical vulnerabilities discovered in popular CI/CD tool
Links:
https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack/
https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/
https://research.openanalysis.net/github/lua/2024/03/03/lua-malware.html
https://resilientcyber.substack.com/p/death-knell-of-the-nvd
https://sysdig.com/blog/cloud-threats-deploying-crypto-cdn/

Mar 20, 2024 • 41min
CROC Talks: Bug Bounty Hunting & Pen Testing with Sam Curry
The NEW exclusive interview with hacker extraordinaire Sam Curry on Crying Out Cloud is out!
Join Eden Naftali and Amitai Cohen as they explore the role of a Bug-Bounty Hunter with Sam Curry:
🔑 Learn about Sam's journey into security research
🛠️ Favorite tools and underrated platforms
🤖 The trustworthiness implications of AI-driven technologies in transportation.
🔒 Vulnerabilities within a major tech company's infrastructure. The tradeoff between scanning gigantic IP ranges and selecting the best research targets.
Important links:
https://samcurry.net/web-hackers-vs-the-auto-industry/
https://samcurry.net/hacking-apple/
https://samcurry.net/points-com/

Feb 22, 2024 • 28min
CROC News: Automotive Code Leak & Midnight Blizzard's Heist
Loading from the Cloud...
Season 2 of "CRYING OUT CLOUD" is here!
Join our hosts, Eden and Amitai, as they dive into the latest cloud stories that we can't wait to share with you
Here's a sneak peek into the season's opening:
🚗 Mercedes-Benz Source Code Exposure:
A public GitHub Repo was exposed - allowing unauthorized access to the company's internal servers, including AWS and Azure subscriptions. The credentials remained publicly accessible for 3-4 months. 😱
🌨️ Midnight Blizzard Hits Microsoft:
Russian actors (Midnight Blizzard) got into Microsoft's network and stole employee emails, finding a misconfigured account with a weak password. Among other things, they tried to find out what Microsoft knew about their activity.
🔐 Ivanti Vulnerabilities:
Ivanti's VPN products exposed vulnerabilities, allowing remote code execution and authentication bypass, exploited by a Chinese Threat Actor.

Dec 21, 2023 • 34min
#15 - Yinon Costica on AI risks, the importance of positivity and his new year's resolutions
🛡️ Join Eden Naftali & Amitai Cohen's exclusive interview with Yinon Costica, as he brings unparalleled expertise to the table. From his beginnings in Israel's 8200 intelligence unit, through Adallom, which was acquired by Microsoft, to co-founding Wiz

Dec 10, 2023 • 35min
#14 - On Executive Orders And AI (Special Guest - Chris Hughes)
🎙️ NEW SPECIAL PODCAST EPISODE WITH @CHRIS HUGHES! 🎙️
Here's a sneak peek into our chat:
🛡️ Join Chris, Amitai, and Eden as they unveil intriguing security nuances between public and private sectors. Gain exclusive insights into FedRAMP, straight from Chris's expertise, and his take on the implications of President Biden's AI order for the cybersecurity landscape.
🌐 How exactly does SBOM adoption act as a shield against supply chain breaches? What other strategies can fortify against such attacks?
🔍 Delve into the post-COVID startup world. Chris touches on the intricacies of the challenges faced, offering a glimpse into how these innovative ventures navigate a changed landscape.
Tune in for a captivating talk below!


