Get a Demo
Under Attack?
Promotional graphic for Upwind featuring a headline: Named in the 10 Cloud, Data and Identity Security Startups to Watch. Logos for The Channel Co. and CRN are displayed at the bottom. The design includes colorful gradient text and lines.

Upwind Named in Top Ten Cloud, Data & Identity Security Startups to Watch

October 11, 2024

Upwind Named in Top Ten Cloud, Data & Identity Security Startups to Watch

We are excited to announce that Upwind has been named by CRN as one of the top ten up-and-coming players in the cloud, identity and data security segments.

The list features startups founded since 2020 with major announcements or achievements in 2024. 

Upwind was also recently named as the Fastest Growing AppSec Company in the IT-Harvest Cyber 150 by analyst Richard Stiennon, as well as receiving an Innovator Spotlight in Cyber Defense Magazine

Founded in 2022, Upwind has raised $80M since its inception and is backed by leading investors including Greylock, Cyberstarts, Craft Ventures, Leaders Fund, Cerca Partners, Stephen Curry’s Penny Jar Capital and Omri Casspi’s Sheva VC.

Contents

Further Reading

KSPM-Agentless-Scanning

Complete KSPM: From Pull Request to Production Runtime

Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…
Upwind MCP Server

Revolutionizing Security Investigations with the Upwind MCP Server

Frontier AI models combined with a rampant rate of new critical vulnerabilities mean speed and context are everything. When a critical production service starts behaving suspiciously, every second spent jumping between different tools and dashboards is a second lost to a potential attacker. At Upwind, we are excited to introduce a game-changer for security teams:…
Security Feed - Threat

No npm Token Required: Inside the AsyncAPI Supply Chain Attack

Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…