bucket malware scanning

Upwind Launches Malware Scanning for Cloud Storage Across AWS, Azure, and GCP

Danilo Michelucci August 14, 2026

Cloud object storage plays a central role in modern applications. Buckets are used to store application assets, exchange files, manage backups, build data pipelines, and share information across services and teams.

That flexibility also makes object storage an attractive attack vector. A malicious file uploaded to a bucket can introduce risk into downstream applications, workloads, and business processes, especially when security teams lack visibility into the file’s contents.

Upwind closes this gap with Malware Scanning for Buckets, available across all three major cloud providers:

  • AWS (Amazon S3)
  • Azure (Blob Storage)
  • Google Cloud (Cloud Storage)

Customers can enable malware scanning for their cloud storage buckets, identify malicious files, and investigate the resulting findings directly within Upwind.

Malware1

Protect object storage across multi-cloud environments

Cloud storage rarely exists in isolation. An organization might use S3 for application assets, Azure Blob Storage for data exchanges, and Google Cloud Storage for analytics, often within the same environment.

Securing each of these with a separate, provider-specific process can create fragmented visibility and additional operational work. Upwind provides a consistent malware-scanning experience across AWS, Azure, and GCP.

This multi-cloud coverage makes it easier to apply a unified security approach as cloud environments grow and storage architectures evolve.

Add malware analysis to bucket scanning

A new malware capability is now available for bucket scanning. When enabled, Upwind performs an additional layer of file analysis to identify malicious content stored in the selected bucket. This extends bucket scanning beyond existing data-risk insights and gives teams a clearer understanding of whether stored files may introduce malware-related risk.

Security teams can use this capability to:

  • Discover malware in cloud object storage
  • Assess malware risk alongside sensitive-data and vulnerability findings
  • Investigate affected storage resources through familiar Upwind threat detection workflows
Malware2

Understand malware risk in context

Finding a file infected with malware is only the beginning. Security teams also need enough context to understand where the file is stored, which resource is affected, and how the finding relates to other risks in the environment.

Upwind surfaces malware risk alongside the sensitive-data and vulnerability findings you already track, so a flagged bucket doesn’t live in a silo of its own.This unified view helps teams evaluate malware findings alongside existing information about sensitive data and vulnerabilities. 

For example, a malicious file located in a bucket containing sensitive data may require different prioritization than the same file in an isolated test resource. Bringing these signals together gives security teams better context for making that decision.

Malware3

Automatically surface threat detections

When Upwind detects a malicious file in a scanned bucket, the finding automatically appears as a threat, and receives a malware tag. 

This connects bucket scanning to the threat-detection workflows security teams already run. Analysts can review malware findings alongside other cloud threats, reducing the chance that a dangerous file remains hidden inside a storage-specific view.

By bringing malware findings into a centralized threat experience, Upwind helps teams move faster from discovery to investigation and remediation.

A unified approach to cloud storage risk

Object storage can contain some of an organization’s most important data, and potentially some of its most dangerous files. Protecting it requires more than understanding whether a bucket is exposed or contains sensitive information. Teams must also be able to identify malicious content and connect it to the broader risk surrounding the resource.

With Malware Scanning for Buckets, Upwind brings malware detection, data-risk context, and cloud threat visibility together across AWS, Azure, and GCP. The result is a clearer, more consistent way to identify dangerous files and prioritize the storage risks that matter most.

Contents

Further Reading

You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS