Cloud Security News – Details, episodes & analysis

Podcast details

Technical and general information from the podcast's RSS feed.

Cloud Security News

Cloud Security News

Cloud Security Podcast Team

News

Frequency: 1 episode/13d. Total Eps: 40

Spotify for Podcasters
Your weekly digest of what you need to know in the world of Cloud Security. We do the hard work for you, so you are always across the important bits.     Brought to you by the team behind the much loved Cloud Security Podcast
Site
RSS
Apple

Recent rankings

Latest chart positions across Apple Podcasts and Spotify rankings.

Apple Podcasts

  • 🇫🇷 France - techNews

    01/05/2026
    #91
  • 🇫🇷 France - techNews

    30/04/2026
    #73
  • 🇫🇷 France - techNews

    29/04/2026
    #65
  • 🇫🇷 France - techNews

    28/04/2026
    #54
  • 🇫🇷 France - techNews

    27/04/2026
    #40
  • 🇫🇷 France - techNews

    26/04/2026
    #34
  • 🇫🇷 France - techNews

    18/04/2026
    #96
  • 🇫🇷 France - techNews

    17/04/2026
    #82
  • 🇫🇷 France - techNews

    16/04/2026
    #73
  • 🇫🇷 France - techNews

    15/04/2026
    #67

Spotify

    No recent rankings available



RSS feed quality and score

Technical evaluation of the podcast's RSS feed quality and structure.

See all
RSS feed quality
To improve

Score global : 43%


Publication history

Monthly episode publishing history over the past years.

Episodes published by month in

Latest published episodes

Recent episodes with titles, durations, and descriptions.

See all

Vulnerabilities discovered in AWS, GCP and Azure

Season 2 · Episode 2

jeudi 26 janvier 2023Duration 07:53

Cloud Security News this week 26 Jan 2023

To read more about this week's stories head to https://cloudsecuritypodcast.tv/cloud-security-news/

Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

  • Nick Frichette has reported a vulnerability that impacts Cloud Trail event logging service. Cloudtrail is what users use in AWS to monitor their API activity so that they can detect any suspicious activity and understand the impacts after a security event. The vulnerability discovered that there is a method to bypass CloudTrail logging for specific IAM API requests via undocumented APIs. . You can read more about this vulnerability here
  • Duo Sreeram KL and Sivanesh Ashok found a SSRF Vulnerability in GCP, which when exploited could make users click onto a malicious URL allowing attacks to gain control of an authorisation token and the user’s GCP projects.
  • CircleCI delivered and have released an incident report which details what happened, how to know if you were impacted, what may help your teams, what they learnt and what they will do next.
  • Corsha, which is API Identity and Access Management software company has released a report - It’s Time To Get Honest About Secrets Management Corsha State of API Secrets Management Report, 2023.
  • Orca security have reported that they found instances where different services were vulnerable to a (you guessed it) Server Side Request Forgery (SSRF) attack. They shared that 2 of the vulnerabilities did not require authentication, meaning that they could be exploited without even having an Azure account.The vulnerabilities were found in Azure Twin Explorer, Azure Functions, Azure API Management Service and Azure Machine Learning Service. You can read their blog here to find out more
  • Techcrunch has reported this week that Dell has acquired an israeli cloud orchestration startup Cloudify for allegedly $100M. Cloudify helps with the management of containers and workloads across hybrid environments. Dell has not publically mad this announcement but Techcrunch has shared that they notice a form they have lodged to indicate this.

Amazon S3 encrypts by default and The CircleCI Breach

Season 2 · Episode 1

samedi 14 janvier 2023Duration 06:26

Cloud Security News this week 14 Jan 2023

To read more about this week's stories head to https://cloudsecuritypodcast.tv/cloud-security-news/

Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

  • According to recent study published by IEEE which I found interesting (which is the Institute of Electrical and Electronics Engineers around since 1963 apparently), “cloud computing (40%), 5G (38%), metaverse (37%), electric vehicles (EVs) (35%), and the Industrial Internet of Things (IIoT) (33%) will be the five most important areas of technology of 2023”
  • Late December, a security engineer at CircleCI received an email notification about a potential attack on his CircleCI account thanks to an AWS CanaryToken placed by him. On Jan 4th, CircleCI advised to rotate any and all secrets stored in CircleCI and published a blog outlining the various ways to do it. 
  • AWS announced on 5 Jan 2023, that Amazon S3 will now automatically apply server-side encryption for each new object. This has been welcomed by AWS users as a good compliance tick and also would assist with those pesky S3 bucket breaches which are still all too common.
  • Unit 42 researchers from Palo Alto Networks recently released a report about Automated Libra, the cloud threat actor behind the freejacking campaign PurpleUrchin, reporting that they had created more than 130,000 accounts on free or limited-use cloud platforms such as Heroku and GitHub.
  • Google has released reports sharing that API endpoints are increasing under attack mostly (no surprises here) due to API misconfigurations. According to their reports, many companies are intending to expand their real-time monitoring of API servers and using (AI/ML) systems to better discover flaws and detect attacks.

JupiterOne announces open source StarBase

Season 2 · Episode 9

mercredi 2 mars 2022Duration 05:00

Cloud Security News this week 2 March 2022

Brought you by Hunters - Find out more about them at www.hunters.ai

To read more about this week's stories head to https://cloudsecuritypodcast.tv/cloud-security-news/

Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

Snyk Acquires Fugue + Amazon CodeGuru Reviewer now detects Apache Log4j

Season 3 · Episode 8

mercredi 23 février 2022Duration 05:51

Cloud Security News this week 23 February 2022 

Brought you by JupiterOne - Find out more about them at https://jupiterone.com/csp

To read more about this week's stories head to https://cloudsecuritypodcast.tv/cloud-security-news/

Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

Azure Launches Azure Payment HSM

Season 2 · Episode 6

jeudi 17 février 2022Duration 04:55

Cloud Security News this week 16 February 2022 - https://cloudsecuritypodcast.tv/cloud-security-news/

Brought you by JupiterOne - Find out more about them at https://jupiterone.com/csp

  • Google’s Cybersecurity Action Team has released Threat Horizon’s report this month. The report can be accessed here
  • Staying in theme with Google Cloud (which also happens to be our theme for this month at Cloud Security Podcast).  This week they have reported a low severity vulnerability in the Linux kernel's  function. The attack uses unprivileged user namespaces and under certain circumstances this vulnerability can be exploitable for container breakout. You can find out more about this vulnerability here. 
  • Azure has announced Azure Payment HSM in preview in East US and North Europe. You can find out more about it here.
  • Cloud Security Alliance’s Technology and Cloud Security Maturity report. You can read the entire report here.
  • Have you heard about the Internet Society or ISOC? Its one of the oldest global nonprofit with a goal of  keeping the Internet as a force for good: open, globally connected, secure, and trustworthy. The researchers at Clario recently discovered an open and unprotected Microsoft Azure blob repository containing millions of files with personal and login details belonging to ISOC members. A blob container named ISOC contained millions of json files that were structured to include login, password and email. Clario reported this to ISOC and the repository was subsequently secured. ISOC also confirmed that they have not seen any instances of malicious access to member data as a result of this issue. You can read more about this here.

Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

Amazon GuardDuty now protects Amazon EKS

Season 2

mercredi 9 février 2022Duration 05:53

Cloud Security News this week 09 February 2022 - https://cloudsecuritypodcast.tv/cloud-security-news/

Brought you by JupiterOne - Find out more about them at https://jupiterone.com/csp

  • Google Cloud has released the Virtual Machine Threat Detection tool as part of their Security Command Center for Premium customer. According to Google’s blog this “is a first-to-market detection capability from a major cloud provider that provides agentless memory scanning to help detect threats like cryptomining malware inside your virtual machines running in Google Cloud.”  For those familiar with AWS Guardduty, how does this compare - share with us on linkedin, twitter or on our website. You can read Google Cloud’s announcement here.
  • Being a Cloud Security Enthusiast, you are probably familiar with the Cloud Security Alliance, they are well known for defining standards, certifications, and best practices for security cloud environments. This week they have released DevSecOps - Pillar 4 Bridging Compliance and Development as part of the DevSecOps Six Pillars series. This document focuses on how compliance can be automated and better relate to security requirements. You can access the full document here. We would love to hear your thoughts about this pillar, so please share your views on www.cloudsecuritypodcast.tv
  • Security Researcher Harsh Jaiswal received a bounty award of $17,576 for whats been described as a “pretty simple” but critical SSRF related to HelloSign’s Google Drive Docs export feature.You can read more about the security team’s response here and the vulnerability report here.
  • Cloudflare, a Silicon Valley provider of content delivery network (CDN) and DDoS mitigation services has launched a public bug bounty program, further to their invite-only program in place since 2018. You can find out more about the program here
  • Tenable, a popular product for vulnerability scanning,  has announced new features to their cloud native application security program, Tenable.cs. You can find our more about tenable and tenable.cs here.
  • Amazon GuardDuty now protects Amazon Elastic Kubernetes Service clusters. You can read more about this here

Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

Google reports Linux Kernel Vulnerabilities

Season 2

mercredi 2 février 2022Duration 05:18

Cloud Security News this week 02 February 2022 

Brought you by JupiterOne - Find out more about them at https://jupiterone.com/csp

  • Google Cloud have reported that 3 security vulnerabilities have been discovered in the Linux kernel, each of which can lead to either a container breakout, privilege escalation on the host, or both.Google have shared that these vulnerabilities affect all GKE node operating systems and Anthos clusters on VMware node operating systems (COS and Ubuntu). Pods using GKE Sandbox are not vulnerable to these vulnerabilities. You can find out more about it here.
  • Safety detectives uncovered and reported on a misconfigured AWS S3 bucket that exposed over 1 million files - “The data we observed related to airport employees from different sites across Colombia and Peru, and there could be entities from other nations with exposed data on the bucket.” The full report can be viewed here.
  • Salesforce now requires all customers to use  multi-factor authentication  MFA in order to access Salesforce products. It's one of the simplest, most effective ways to prevent unauthorized account access and safeguard your data and your customers' data. Let us know what you think of this change and more on this can be found here.
  • Markets and Markets has shared that the “global cloud security market size is expected to grow from USD 40.8 billion in 2021 to USD 77.5 billion by 2026”. You can find out more here
  • Cloud security and compliance automation startup Anitian this week closed a $55 million Series B funding bringing their funding to date to $71 million. In a company blog CEO, ​​Rakesh Narasimhan shared that the new funding is a significant milestone in accelerating their mission to provide the most innovative cloud security, compliance automation, and cloud security posture management (CSPM) platforms that enable enterprises of all sizes with the fastest path to security and compliance in the cloud. You can find out more about them here.
  • Check Point has acquired Spectral, an Israeli startup who have developer-first security tools designed by developers for developers. With this acquisition, Check Point extends its cloud solution, Check Point CloudGuard, with developer-first security platform, to provide a range of cloud application security use cases including Infrastructure as Code (IaC) scanning and hardcoded secrets detection. Find out more here.

Podcast Twitter - Cloud Security Podcast (@CloudSecPod)

Instagram - Cloud Security News 

If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:

- Cloud Security Podcast:

McFee and FireEye join forces for XDR

mercredi 26 janvier 2022Duration 03:51

Cloud Security News this week 26 Jan 2022

  • Early December on Cloud Security News, we shared that Symphony Technology Group had acquired McAfee for 4 Billion along with FireEye for 1.2 Billion. The merger of these two companies has now form Trellix, which aims to be a leader in extended detection and response (XDR). In their blog post Trellix shared that  “Customers can expect Trellix’s living security platform to deliver bold innovation across the XDR market.”  - “with automation, machine learning, extensible architecture, and threat intelligence.”  You can find out more about Trellix and read their blog post here and let us know if you are excited about this merger?
  • Orca Security is back in the news this week, not for their funding round or their vulnerability findings in AWS. They have made their 1st acquisition: RapidSec, an Israeli cybersecurity startup that protects web applications from client-side attacks. RapidSec’s software allows for detection of  web-application misconfigurations and deviations from best practices. Orca has indicated that it  plans to integrate these web services and API security technologies into its agentless cloud security platform. You can read more about this acquisition here.
  • Cloud Security Firm Polar Security that has emerged from Stealth With $8.5 Million Seed Funding. They are a Tel Aviv, Israel-based cloud security company that aims to provide visibility into companies’ cloud data storage to allow security teams to secure the data and avoid compliance problems. You can find out more about them here
  • Hunters.ai announced that  it has raised a $68 million Series C round bringing their total funding to date to $118 million. Hunters share in their blog that  “Never before has it been more lucrative to be a cyber criminal” and “On the defenders’ side, we see organizations struggling to keep pace. As technology advances and more tools are being used, the attack surface grows and the number of security products used by these organizations increases.” This is where Hunter.ai believes they can help with their Extended Detection and Response (XDR) platform used by Security Operations Center (SOC) teams to detect, investigate and stop threats. You can find out more about them here

Podcast Twitter - Cloud Security Podcast (@CloudSecPod)

Instagram - Cloud Security News 

If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:

- Cloud Security Podcast:

- Cloud Security Academy:

Remote Access Trojans target Public Cloud Infrastructure

Season 2 · Episode 3

mercredi 19 janvier 2022Duration 07:06

Cloud Security News this week 19 Jan 2022

  • Cisco Talos Researchers have shared in a blog last week that  a trio of remote access Trojans (RATs)—Nanocore, Netwire and AsyncRAT—are being spread in a campaign that taps public cloud infrastructure and is primarily aimed at victims in the U.S., Italy and Singapore. According to the blog “Threat actors are increasingly using cloud technologies to achieve their objectives without having to resort to hosting their own infrastructure,” and “cloud services like Azure and AWS allow attackers to set up their infrastructure and connect to the internet with minimal time or monetary commitments. It also makes it more difficult for defenders to track down the attackers’ operations.”  Read more about this here.
  • Netskope also released a blog last week about Malwares. Interestingly their research which surveyed millions of users worldwide from January 1, 2020 to November 30, 2021 found that Cloud-delivered malware is now more prevalent than web-delivered malware, accounting for 66%, up from 46% last year. They also found that Google Drive is the top app for most malware downloads and Cloud-delivered malware via Microsoft Office nearly doubled from 2020 to 2021. Read the report here
  • Vulnerability in AWS’s cloudformation service that was discovered and shared by Orca Security. Orca Security confirmed that  AWS completely mitigated within 6 days of their submission.If you want to know more about their discovery, you can read it here
  • The US government is reportedly reviewing the cloud computing arm of Chinese ecommerce giant Alibaba to determine whether or not it poses a risk to national security.” As reported by Reuters, the Biden administration launched the probe to find out more about how Alibaba Cloud stores the data of US clients including personal information and intellectual property and to see if the Chinese government could gain access to it. You can read Reuters report here
  • Sysdig’s platform who were recently valued at 2.5 Billion have expanded their cloud security offering to Azure Cloud aswell. . You can find out more about them here 

Podcast Twitter - Cloud Security Podcast (@CloudSecPod)

Instagram - Cloud Security News 

If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:

- Cloud Security Podcast:

- Cloud Security Academy:

UK Financial Regulators monitoring Cloud Providers Closely

Season 2 · Episode 2

mercredi 12 janvier 2022Duration 04:25

Cloud Security News this week 12 Jan 2022

  • UK’s financial regulators - The Prudential Regulation Authority is looking to increase it’s monitoring of Cloud providers like AWS, Azure and Google Cloud. According to Financial times, they are looking to gain more access to data from these cloud providers because the impact outages and cyberattacks have on British Banks. They are looking at implementing more robust outages and disaster recovery tests given the increasing reliance UK banks have on a handful of cloud providers. A lot of major British banks have partnerships with cloud providers “AWS has announced deals with Barclays and HSBC, while Lloyd Banking Group holds partnerships with Google Cloud and Microsoft Azure.”. There is an increasing concerns about the impacts on the banks should these cloud providers experience outages. You can view the financial times article here
  • Speaking of regulators and how they are dealing with cloud providers, a few weeks ago in December Chinese regulators have “suspended an information-sharing partnership with Alibaba Cloud Computing” over concerns that it failed to promptly report and address a cybersecurity vulnerability. According to 21st Century Business Herald, citing a recent notice by the Ministry of Industry and Information Technology “Alibaba Cloud did not immediately report vulnerabilities in the popular, open-source logging framework Apache Log4j2 to China's telecommunications regulator”.This comes after, according to Reuters “The Chinese government has asked state-owned companies to migrate their data from private operators such as Alibaba and Tencent to a state-backed cloud system by next year.” From what we understand, there is no statement from Alibaba Cloud on this yet. You can read more about this here.
  • Gartner's Report can be found here.
  • Redhat's Report can be found here.

Podcast Twitter - Cloud Security Podcast (@CloudSecPod)

Instagram - Cloud Security News 

If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:

- Cloud Security Podcast:

- Cloud Security Academy:


Related Shows Based on Content Similarities

Discover shows related to Cloud Security News, based on actual content similarities. Explore podcasts with similar topics, themes, and formats, backed by real data.
All-In with Chamath, Jason, Sacks & Friedberg
Leap Academy with Ilana Golan
The CMO Podcast
Thinking Elixir Podcast
Programming Throwdown
FT News Briefing
Marketing Trends
Risky Business
Kubernetes Podcast from Google
BrakeSec Education Podcast
© My Podcast Data