Introducing Security Risks: A Unified Model for Understanding Cloud Risks

Security-Risks

Cloud security teams face an overwhelming amount of data. Misconfigurations, vulnerabilities, identity risks, and exposures often live in separate tools and dashboards, making it difficult to see how they connect. The real challenge is understanding how these signals intersect to create true risk. That’s why we are excited to introduce Upwind Security Risks – a unified […]

Upwind Strengthens Cloud Identity Security with New Microsoft Entra ID Detection Coverage

entra_id

We are thrilled to announce that Upwind has expanded its Microsoft Entra ID (formerly Azure Active Directory) detection coverage to provide deeper visibility into identity changes, privilege escalation, and credential misuse across Azure environments. These new detections help security teams identify and respond to identity-driven threats faster, before they can compromise the tenant or persist […]

Upwind Enables Smarter, More Efficient, Security with Sensor Improvements

Sensor Improvements

We are excited to share the latest improvements to our eBPF-powered sensor, the foundation of our runtime security platform. By continuously enhancing how the sensor observes and protects Kubernetes environments, we’re making security both more effective and more efficient for our customers. As part of this advancement, we are introducing container image scan jobs, a […]

Upwind AI Security: Securing Every Layer of the AI Stack

AI Security

Introduction: AI in the Wild AI is no longer confined to R&D teams and academic benchmarks. It’s powering help desks, generating product recommendations, writing code, and increasingly connecting directly to critical systems via toolchains and APIs. These new capabilities come with new risks, and security teams are being asked to manage systems that behave unpredictably […]

Upwind Expands Threat Detection with Native Azure Log Analytics Integration

Azure Activity Logs-c

Upwind is excited to announce a new integration that brings deeper visibility and faster threat detection to Microsoft Azure environments. With native support for Azure Log Analytics and Activity Logs, customers can now detect risks and respond to threats across Azure with greater precision, especially around administrative activity, access patterns, and configuration changes. This release […]

The Salesloft-Drift Breach: A Wake-Up Call for API Security

salesloft drift-b4x

Attack Path: From Source Code to API Abuse The recent Salesloft-Drift breach that compromised hundreds of organizations represents a new category of cyber threat that every security team needs to understand. This wasn’t a traditional hack; it was a sophisticated attack that exploited the very foundation of modern SaaS integrations: OAuth tokens and API trust […]

Upwind Modernizes PCI-DSS for Cloud-Native Security

PCI DSS

We’re introducing the Upwind Framework for PCI-DSS to help organizations meet one of the most widely adopted security standards. This release is part of Upwind’s broader mission to make compliance continuous and directly tied to runtime environments. In this blog, we will explain what PCI-DSS is and why it matters, highlight the growing challenges of […]

Streamline Compliance & Auditing with Upwind’s Configurations Dashboard

Configurations Dashboard

If you’re responsible for cloud security and compliance, you know the drill. Misconfigurations pile up across environments, frameworks keep updating, and leadership wants to see progress – all while your team is already stretched thin. The stakes are high. A single overlooked configuration can lead to major gaps in compliance, or worse, leave sensitive data […]

Harbor Shift Left: Bringing Runtime Intelligence to Container Security

Harbor Shift Left

Picture this: your development team is racing to deploy a critical update, but security scanning brings everything to a halt. The scanner reports 47 vulnerabilities, but which ones actually matter? Which are exploitable in production? And most importantly, should you block the deployment or proceed? This is the daily reality for most DevOps teams. Traditional […]

Upwind Now Supports CloudTrail Log Aggregation for More Accurate Detections

AWS Cloud Logs

A security team at a large financial services company once spotted a troubling pattern: a low-privilege IAM role listed IAM users, created an inline policy, and then assumed a higher-privilege role. Each action looked routine on its own and slipped past their detection system, which analyzed events in isolation. Only later, during a manual review, […]