Get a Demo
Under Attack?
A colorful flowchart depicting a network analysis, with nodes connected by lines branching out from a central icon. Two pop-up boxes to the right highlight specific analyses, mentioning the photo10 package and port 80 internet access.

Launching Upwind’s Runtime Vulnerability Management

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Jonathan Cohen September 01, 2023

Launching Upwind’s Runtime Vulnerability Management

As businesses continue to become hybrid-cloud or cloud-native, runtime detection and response is moving to the forefront as one of the most pressing challenges security leaders face today. With the growing sprawl of cloud attack surfaces, prioritizing vulnerabilities is a priority for security leaders, especially since the severity of risks and vulnerabilities are most accurately understood within the context of runtime environments. Gartner’s recent emerging technology report further emphasized that runtime visibility and detection are critical aspects of understanding threats and vulnerabilities, and that security leaders must adopt cloud technologies that address these demands for more data and analysis.

For that reason, we are very excited to announce that today, we are launching our Runtime Vulnerability Management Feature that will help security teams detect and prioritize exploitable vulnerabilities in their cloud runtime environments. 

For security teams, the expanding attack surfaces across cloud environments make identifying and remediating runtime vulnerabilities an incredibly labor-intensive, time-consuming task that takes teams hours or days to get to the root cause of vulnerabilities. With economic cutbacks and the need for highly trained security professionals, this time spent hunting down vulnerabilities not only overtaxes teams that are already working at full capacity, it also leaves organizations open to threats looking to exploit their most critical vulnerabilities. 

Our Vulnerability Management Feature solves this problem by cutting through the noise and sending you only the most critical alerts, which the platform does by prioritizing vulnerabilities in your environment that can actually be exploited by threats while ignoring those that don’t pose a threat to your organization.

Vuln-list-1-1024x482

We do this by mapping your cloud infrastructure and resources and creating security baselines based on your cloud environment’s known, normal behavior while adding the context of CI/CD events, git/code changes, k8s audit logs, Azure activity logs and cloud activities. By creating a security baseline and adding that grid of context from runtime events, Upwind is able to immediately distinguish which vulnerabilities can be exploited, such as critical vulnerabilities that are in-use, can be accessed by the Internet and have paths to sensitive data. By doing so, Upwind saves your security team countless hours of work and points them directly to the root cause of critical vulnerabilities. 

“There are many companies that see runtime security as a feature, but we see it as the solution”

“There are many companies that see runtime security as a feature, but we see it as the solution,” said Amiram Shachar, CEO of Upwind. “We tackle runtime with mile-deep context that gives you full visibility and control over your cloud environment and helps you focus only on your most critical vulnerabilities.”

Upwind’s Runtime Vulnerability Feature lets you:

  • Reduce the attack surface dramatically – Find software packages that are not in use and remove them from builds.
  • Focus on what matters – Solve only the vulnerabilities that introduce a real risk to your business.
  • Cut >90% of your CVEs noise
    Prioritize vulnerabilities based on real environmental variables:
    • Active Internet traffic
    • Communication with metadata services (such as IMDSv1)
    • Internet-facing
    • Invoked packages
    • Exploitability
    • Available fix
  • Clear Remediation Save thousands of hours by solving the most critical alerts at the container/VM image level.
  • CI/CD awareness – Go directly to the root cause of vulnerabilities with context from CI/CD, & git/code changes.

Our new Runtime Vulnerability Feature helps security teams cut through the noise to prioritize critical vulnerabilities and investigate the root cause of CVEs. You can learn more about our runtime detection and response capabilities in the Upwind docs (login needed). If you would also like to see a live demo of the Upwind product, we would love to connect with you. 

401 Authorization Required

401 Authorization Required


nginx
Contents

Further Reading

Superhuman AI

Security AI Needs an Honest Scoreboard: What It’s Superhuman At, and Where It Comes Up Short

If you follow AI at all, you know the leaderboards. Every few weeks a model takes the top spot, and we all check where our favorite landed. But a leaderboard only tells you who's ahead, and it stays quiet about where any of those models still come up short. Which, conveniently, is the part that…
Focus Mode

Find What Matters with Upwind Focus Mode

Focus Mode is now available in the Upwind platform, giving security teams a faster, more focused way to work. Instead of navigating across the platform, you can switch to Focus Mode to slice and dice the Upwind platform by Vulnerability Management, Cloud Security Posture, Attack Surface Management, Administration, or Threats, and starting next week, AI…
Early Advisories

Introducing Early Advisories: Turn Emerging Threats into Action

We’re excited to introduce Early Advisories as part of the Upwind platform. Powered by Upwind's security research team, Early Advisories notify customers about emerging threats, including zero-days and supply chain attacks, before they receive a CVE identifier. Early Advisories are published directly into the Vulnerabilities module alongside CVE-based findings and automatically correlated with your live…