This week's articles
Report: Voice of the SOC 2023
#monitor, #strategy
Discover insights and recommendations from a survey of 900 security professionals, and the takeaways for leadership.
malicious-packages
#defend, #supply-chain
A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
Changing Sealed Secrets Passwords in Kubernetes
#build, #kubernetes
There are plenty of articles that focus on installing Bitnami's Sealed Secrets application and creating your first Sealed Secret within Kubernetes. However, most article do not cover how to change passwords defined within a Sealed Secret.
|
|
Tools
kexp
Understand Kubernetes - the visual way. Not yet another attempt to manage production clusters in the browser.
ipv4-usage-monitoring-for-aws
This script allows customers to iterate through all regions and all accounts in an organization to enumerate all public IPs and flag certain IPs that may be unnecessary for further investigation.
marvin
Marvin is a CLI tool that scans a k8s cluster by performing CEL expressions to report potential issues, misconfigurations and vulnerabilities.
|
|
Sponsor
Opal – Modern Identity Security Opal is designed to give teams the building blocks for identity-first security: view authorization paths, manage risk, and seamlessly apply intelligent policies built to grow with your organization.
Opal is used by best-in-class security teams today, such as Blend, Databricks, Exelixis, Figma, Scale AI, and more. There is no one-size-fits-all when it comes to access, but Opal provides the data foundation to scale least privilege the right way.
|
|
|
Business News
-
Trust & Safety Tycoon lets you simulate the most agonizing job in tech (source)
-
Wiz launches support for Google Workspace, helping organizations secure Google Cloud identities (source)
-
Orca Security Integrates with Google Workspace to Strengthen Visibility and Security (source)
-
Fingerprint, a device security company that helps developers prevent fraudulent activity on websites, announced a $33M Series C (source)
-
Zygon bags $3m in seed funding to prevent SaaS security risk (source)
-
SecureW2 raises $80M to help companies adopt passwordless approach to zero-trust security (source)
-
Amazon quietly rolls out support for passkeys, with a catch (source)
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌 If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|