Dec 06, 2023NewsroomAccess Management / Cloud Security Threat actors can take advantage of Amazon Web Services Security Token Service (AWS STS) as a way to infiltrate cloud accounts and conduct follow-on attacks. The service enables threat actors to impersonate user identities and roles in cloud environments, Red Canary researchers Thomas Gardner and Cody Betsworth said in a … [Read more...] about Threat Actors Can Leverage AWS STS to Infiltrate Cloud Accounts
cloud
5 best practices for Elastic Cloud production deployment
Proper planning of a deployment architecture is one of the critical factors in unlocking the Elastic Stack potential, leading to better operational efficiency and optimum performance.Highlighted below are parameters that influence the architecture. Based on the organization's needs, customers are encouraged to dive deeper into these aspects using the mentioned resources.Node … [Read more...] about 5 best practices for Elastic Cloud production deployment
CrowdStrike Demonstrates Cloud Security Leadership at AWS re:Invent
CrowdStrike is honored to be named Partner of the Year for several 2023 Geo and Global AWS Partner Awards at Amazon Web Services re:Invent 2023, where we are participating this year as a Diamond Sponsor. We are also proud to be a launch partner for AWS Built-in and achieve two AWS competencies. These accomplishments demonstrate our forward-thinking approach to cloud security … [Read more...] about CrowdStrike Demonstrates Cloud Security Leadership at AWS re:Invent
How CoreWeave Uses CrowdStrike to Secure Its High-Performance Cloud
CoreWeave is a specialized GPU cloud provider powering the AI revolution. It delivers the fastest and most consistent solutions for use cases that depend on GPU-accelerated workloads, including VFX, pixel streaming and generative AI. CrowdStrike supports CoreWeave with a unified, AI-native cybersecurity platform, protecting CoreWeave’s architecture by stopping breaches. What … [Read more...] about How CoreWeave Uses CrowdStrike to Secure Its High-Performance Cloud
Enable Elastic Observability for Google Cloud Platform metrics
Developers and SREs choose to host their applications on Google Cloud Platform (GCP) for its reliability, speed, and ease of use. On Google Cloud, development teams are finding additional value in migrating to Kubernetes on GKE, leveraging the latest serverless options like Cloud Run, and improving traditional, tiered applications with managed services.Elastic Observability … [Read more...] about Enable Elastic Observability for Google Cloud Platform metrics
Kinsing Actors Exploiting Recent Linux Flaw to Breach Cloud Environments
Nov 03, 2023NewsroomCloud Security / Linux The threat actors linked to Kinsing have been observed attempting to exploit the recently disclosed Linux privilege escalation flaw called Looney Tunables as part of a "new experimental campaign" designed to breach cloud environments. "Intriguingly, the attacker is also broadening the horizons of their cloud-native attacks by … [Read more...] about Kinsing Actors Exploiting Recent Linux Flaw to Breach Cloud Environments
How to get the most from your Elastic Cloud trial
Elastic Cloud is a cloud-based managed service offering provided by Elastic®. Elastic Cloud allows customers to deploy, manage, and scale their Elasticsearch® clusters and other components of the Elastic Stack in Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure without the need to manage the underlying infrastructure, enabling users to focus on … [Read more...] about How to get the most from your Elastic Cloud trial
Take control of your Elastic Cloud spend with data-driven insights
As we continue to expand our product offerings, new products, and services will be integrated into the usage page. The latest addition to this offering is Synthetic Monitoring. This feature offers insights into the utilization and expenses associated with synthetics products, making it easier to manage and optimize your overall spending.We encourage you to explore the enriched … [Read more...] about Take control of your Elastic Cloud spend with data-driven insights
Elastic wins CyberSecurity Breakthrough Award for Cloud Platform of the Year 2023
Elastic Security for Cloud also includes cloud-native vulnerability management capabilities. This continuously uncovers vulnerabilities in AWS EC2 with zero resource utilization on workloads. Elastic identifies, reports, and guides remediation of these vulnerabilities to help you identify and respond to potential risk.Elastic Security for Cloud is also supported by Elastic … [Read more...] about Elastic wins CyberSecurity Breakthrough Award for Cloud Platform of the Year 2023
Scattered Spider Getting SaaS-y in the Cloud
LUCR-3 overlaps with groups such as Scattered Spider, Oktapus, UNC3944, and STORM-0875 and is a financially motivated attacker that leverages the Identity Provider (IDP) as initial access into an environment with the goal of stealing Intellectual Property (IP) for extortion. LUCR-3 targets Fortune 2000 companies across various sectors, including but not limited to Software, … [Read more...] about Scattered Spider Getting SaaS-y in the Cloud