Get a Demo
Under Attack?
A software interface displays a network diagram with orange nodes connected by lines, representing a system architecture. On the right, a panel shows detailed information about a node labeled Spark, including CPU usage and deployment options.

Identify Threats & Risks in a LinkerD-based Kubernetes Environment

Denise Ashur November 01, 2023

Identify Threats & Risks in a LinkerD-based Kubernetes Environment

We are excited to announce a new capability – LinkerD awareness. 

LinkerD is a service mesh that allows organizations to secure, connect and monitor traffic to Kubernetes. Upwind will now identify LinkerD sidecars and proxies, in addition to our current Istio monitoring, and use this information as context for our threat detection and risk prioritization engine. This gives you increased visibility of your entire network flow, providing you with advanced infrastructure context all the way from endpoints through virtual network devices.

Use this new capability to gain even more understanding of resource behavior, identify internet exposure threats and receive needed insights into your network flows with Upwind’s LinkerD awareness.

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS