Get a Demo
Under Attack?
A promotional graphic for Upwind featuring the text Evaluate Your Vulnerability Resolution Over Time. It shows colorful umbrellas and abstract shapes against a gradient blue to sand-colored background.

Evaluate Your Vulnerability Resolution Over Time

Denise Ashur February 19, 2024

Evaluate Your Vulnerability Resolution Over Time

We are excited to announce a new section in the Upwind Platform – the Vulnerability Dashboard. 

The Vulnerability Dashboard will give you the ability to see both an overview of your current critical vulnerabilities and the state of your vulnerabilities over time. 

Get an instant overview of your current vulnerabilities, including:

  • the most critical vulnerabilities that should be prioritized for remediation 
  • the amount of vulnerabilities by severity
  • the number of CVEs and severities for Kubernetes workloads, scaling groups, and hosts. 
  • top container images with the highest number of critical CVEs.
Vulnerabilities-dashboard-mock-A-1024x574

The Vulnerability Dashboard will also give you high-level insights into your vulnerability management over time, including: 

  • how your environment was exposed over a period of time 
  • how many new vulnerabilities were introduced versus how many were resolved 
  • the number of CVEs count and severities for each workload type over a period of time
Vulnerabilities-dashboard-mock-B-1024x532

Use Upwind’s Vulnerability Dashboard to easily get a high-level overview of the state of your vulnerabilities, and use this feature to evaluate and track your organization’s progress with vulnerability remediation over time. 

Contents

Further Reading

Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Custom-Reporting-Hero

Security Reporting Built Around Your Program

We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…
Blue-agent-blog

Introducing the Upwind Blue Agent: Autonomous Threat Investigation for the SOC

We’re excited to announce that the Upwind Blue Agent is now available in Beta. Blue is an AI-powered SOC investigator that autonomously investigates Upwind Threat Stories end to end. It gathers and correlates security context across the customer environment, evaluates the available evidence, and delivers one of three clear verdicts: Each verdict includes supporting reasoning…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS