Get a Demo
Under Attack?
cloud-parity-b

Expanding CSPM with Runtime Advantage: Deep Data Scanning & Multi-Cloud Parity

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Moshe Hassan December 03, 2025

We are excited to announce a major expansion of the Upwind Runtime Attack Surface Management. This release extends support for GCP, OCI, and Azure resources, bringing true multi-cloud parity while deepening AWS support with expanded support for AWS Lambda, SNS, Elasticache, and Redis.

Beyond coverage, we are introducing Deep Data Scanning – a new ASM playbook capability that goes beyond metadata to validate data exfiltration risks by inspecting content itself using trained models to identify unique and critical data.

Paired with a refreshed UI and on-demand re-scanning, this release gives teams the evidence they need to move faster and total modularity to playbooks.

Expanded Runtime Coverage 

We have extended our sensor-based and agentless visibility to match our deep AWS coverage, ensuring you have a unified runtime view across all major providers.

  • Google Cloud Platform (GCP) – We have brought full parity to GCP with new support for Compute Engine hosts and serverless Cloud Functions. This expansion includes deep visibility into your data and infrastructure layers, covering Cloud Storage buckets, Cloud SQL, and Memorystore.
  • Microsoft Azure – Our Azure coverage now mirrors our deep AWS capabilities, delivering full runtime support for Azure Virtual Machines and Azure Functions. We have also expanded our granular visibility to critical data services, including Azure SQL Database, Blob Storage containers, and Azure Cache for Redis.
  • AWS – Building on our existing foundation, we have further deepened our AWS sensor capabilities to cover serverless and messaging architectures. This release adds extended runtime visibility for AWS Lambda, Amazon SNS, and ElastiCache & Redis.
  • Oracle Cloud Infrastructure (OCI) – We are extending the same runtime-first visibility to OCI, starting with core compute and serverless coverage plus critical data services. This includes runtime support for OCI Compute instances and Oracle Functions, to help teams identify exposed assets, risky access paths, and data exfiltration conditions.

New Capability: Deep Data Scanning & Exfiltration Risk

Our validation engine now goes deeper. Instead of just checking if a resource is accessible, we can now verify if sensitive data is exposed.

  • Content-Aware Playbooks: New validation steps scan the actual contents of storage objects (S3, Cloud Storage, Blob Storage) and databases to identify PII, secrets, and sensitive intellectual property.
  • Exfiltration Simulation: The playbook now simulates “read” operations to confirm if an attacker could successfully exfiltrate data, moving risk assessment from “potential” to “proven.”
s3
  • AI-Powered Asset Identification: We are leveraging specialized AI and ML models to automatically discover mission-critical assets and functions. This intelligence allows us to differentiate between standard data and high-value targets, significantly increasing risk clarity for your team.

Experience & Usability Upgrades

  • New UI & Visual Indication: We’ve overhauled the findings interface. Critical, verified risks now feature distinct visual indicators (badges and high-contrast highlights) across the entire system, from the topology map to the alerts list, ensuring validated risks never get lost in the noise.
Configuration-finding-list
  • On-Demand Re-Scan: You no longer need to wait for the next scheduled interval. Trigger a specific validation playbook or full asset re-scan instantly with a single click to verify remediation immediately. You can now even simulate specific parts of a playbook without running the entire sequence.
RDS

What’s Next

We are already working on the next wave of enhancements to give you even more control over your runtime security:

  • Playbook Management: A new builder interface allowing you to customize validation logic, edit existing playbooks, and create your own risk scenarios.
  • Discovery vs. Aggressive Mode: As our attack engine evolves, we are introducing distinct operational modes. Discovery Mode will focus on read-only actions to identify risks, while Aggressive Mode will run impactful playbooks – ranging from CVE exploitation to bucket write actions, to prove exploitability where necessary.
  • Internal Cloud Testing: New capabilities to test your environment from the inside, enabling the validation of identity risks and lateral movement paths.
  • Oracle Cloud (OCI) Support: Extending our runtime visibility and attack surface management to Oracle Cloud Infrastructure.

To learn more about Upwind’s runtime security enhancements, schedule a demo with our team today.

Contents

Further Reading

OpenAI Breach

Everyone Read the OpenAI Breach as a Model Story, But It Was a Runtime Story

Key Takeaways Autonomous AI agents can now break out of a sandbox, cross an internal network, and breach a production system with no human at the keyboard. OpenAI's evaluation that hacked Hugging Face this month is the clearest proof on record. Most of the coverage read it as a story about a model turning dangerous.…
upwind-identities

Introducing the Upwind Identity Graph: End-to-End Identity Security

Identity used to be treated as a directory problem: find the user, inspect the groups, review the assigned roles, and decide whether the account has too much access. That model no longer matches the cloud. A single person may authenticate through Okta, inherit permissions from multiple groups, receive role assignments in more than one cloud,…
AI-Graph

Introducing the Upwind AI Graph: Extending AI Inventory Beyond Cloud Infrastructure

As enterprise adoption of artificial intelligence accelerates, modern AI infrastructure has expanded far beyond traditional cloud perimeters. Securing enterprise AI today requires complete visibility across four distinct operational layers: Traditional cloud security tools stop at the cloud provider boundary. When enterprise teams connect directly to external AI Providers, security teams lose sight of access paths,…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS