Get a Demo
Under Attack?
bucket malware scanning

Upwind Launches Malware Scanning for Cloud Storage Across AWS, Azure, and GCP

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Danilo Michelucci August 14, 2026

Cloud object storage plays a central role in modern applications. Buckets are used to store application assets, exchange files, manage backups, build data pipelines, and share information across services and teams.

That flexibility also makes object storage an attractive attack vector. A malicious file uploaded to a bucket can introduce risk into downstream applications, workloads, and business processes, especially when security teams lack visibility into the file’s contents.

Upwind closes this gap with Malware Scanning for Buckets, available across all three major cloud providers:

  • AWS (Amazon S3)
  • Azure (Blob Storage)
  • Google Cloud (Cloud Storage)

Customers can enable malware scanning for their cloud storage buckets, identify malicious files, and investigate the resulting findings directly within Upwind.

Malware1

Protect object storage across multi-cloud environments

Cloud storage rarely exists in isolation. An organization might use S3 for application assets, Azure Blob Storage for data exchanges, and Google Cloud Storage for analytics, often within the same environment.

Securing each of these with a separate, provider-specific process can create fragmented visibility and additional operational work. Upwind provides a consistent malware-scanning experience across AWS, Azure, and GCP.

This multi-cloud coverage makes it easier to apply a unified security approach as cloud environments grow and storage architectures evolve.

Add malware analysis to bucket scanning

A new malware capability is now available for bucket scanning. When enabled, Upwind performs an additional layer of file analysis to identify malicious content stored in the selected bucket. This extends bucket scanning beyond existing data-risk insights and gives teams a clearer understanding of whether stored files may introduce malware-related risk.

Security teams can use this capability to:

  • Discover malware in cloud object storage
  • Assess malware risk alongside sensitive-data and vulnerability findings
  • Investigate affected storage resources through familiar Upwind threat detection workflows
Malware2

Understand malware risk in context

Finding a file infected with malware is only the beginning. Security teams also need enough context to understand where the file is stored, which resource is affected, and how the finding relates to other risks in the environment.

Upwind surfaces malware risk alongside the sensitive-data and vulnerability findings you already track, so a flagged bucket doesn’t live in a silo of its own.This unified view helps teams evaluate malware findings alongside existing information about sensitive data and vulnerabilities. 

For example, a malicious file located in a bucket containing sensitive data may require different prioritization than the same file in an isolated test resource. Bringing these signals together gives security teams better context for making that decision.

Malware3

Automatically surface threat detections

When Upwind detects a malicious file in a scanned bucket, the finding automatically appears as a threat, and receives a malware tag. 

This connects bucket scanning to the threat-detection workflows security teams already run. Analysts can review malware findings alongside other cloud threats, reducing the chance that a dangerous file remains hidden inside a storage-specific view.

By bringing malware findings into a centralized threat experience, Upwind helps teams move faster from discovery to investigation and remediation.

A unified approach to cloud storage risk

Object storage can contain some of an organization’s most important data, and potentially some of its most dangerous files. Protecting it requires more than understanding whether a bucket is exposed or contains sensitive information. Teams must also be able to identify malicious content and connect it to the broader risk surrounding the resource.

With Malware Scanning for Buckets, Upwind brings malware detection, data-risk context, and cloud threat visibility together across AWS, Azure, and GCP. The result is a clearer, more consistent way to identify dangerous files and prioritize the storage risks that matter most.

Contents

Further Reading

API-ASM Blog

Validate the Real-World Exposure of Your APIs with Upwind Attack Surface Management

Your APIs are probably the least-monitored component of your attack surface. They multiply faster than any team can document, and most scanners only ever pick up the ones you already know about. But that gap just got smaller. Upwind’s Attack Surface Management capabilities now provide a unified view of cloud and API exposure, helping security…
gemini-svg

Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Executive Summary Upwind recently observed multiple Advanced Persistent Threat (APT) groups actively exploiting CVE-2026-72898. This vulnerability - an unauthenticated SQL injection in the Metabase password reset endpoint carrying a critical CVSS score of 10.0, was actively exploited as a zero-day before a patch became available. An unauthenticated remote attacker can craft a malicious SQL injection…
Buyers Demos

Why Buyers Remember Solving a Demo, Not Watching One

Key Takeaways I recently sat down with Upwind Solutions Architect, Evan Grace to learn more about his process. After some intros, he told me about his new hobby, hydroponics. For those who don’t know, hydroponics is a method of growing plants without soil. This was unbelievable to me but after Evan explained his deep dive…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS