scanners-only

Refining Your Workflow: A Faster, More Intuitive Upwind Experience

Sam Langrock April 10, 2026

Refining Your Workflow: A Faster, More Intuitive Upwind Experience

At Upwind, our goal has always been to provide deep visibility into your cloud environment without the “dashboard fatigue” that plagues so many security teams. We know that in the heat of a security incident, every second counts—and every click matters.

That’s why we’ve rolled out a series of Platform Navigation Updates designed to make your workflow more intuitive, structured, and lightning-fast. These changes align related capabilities under unified domains, ensuring that whether you are hunting for a rogue API or auditing machine identities, the path is exactly where you’d expect it to be.

Unified Inventory & Identity Management

We have centralized asset management to give you a more holistic view of your attack surface. By aligning these capabilities, you can now manage your entire cloud footprint from a single, logical location:

  • API Catalog: Now conveniently located under Inventory.
Screenshot-2026-04-09-at-6.40.15-PM-1024x643
  • Identities (Human & Non-Human): Both user and machine identities are now housed under Inventory > Identities, simplifying how you audit permissions and access.
Screenshot-2026-04-09-at-7.55.10-PM-1024x643
  • SBOM Explorer: Your Software Bill of Materials now has a dedicated home under the Inventory tab for better software supply chain visibility.
Screenshot-2026-04-09-at-7.56.16-PM-1024x643
  • Organizations & Accounts: These have transitioned to Inventory, providing a clear, top-down view of your multi-cloud accounts and structure.
Screenshot-2026-04-09-at-7.56.54-PM-1024x643

Focused Feeds for Rapid Response

To help you separate high-level discovery from deep-dive investigation, we’ve introduced dedicated views for your most critical security data:

  • Security Issues: This is now a dedicated tab with a Feed View. This update puts your most urgent findings in the spotlight, allowing you to filter, prioritize, and remediate without unnecessary noise.
Screenshot-2026-04-09-at-7.59.05-PM-1024x643
  • Secrets: To help you better protect sensitive credentials, Secrets has moved to a dedicated feed tab under the Data domain.
Screenshot-2026-04-09-at-6.41.31-PM-1024x643

These updates are about more than just moving buttons—they are part of our commitment to creating a seamless UX that aligns with how modern security practitioners actually work. By streamlining the interface, we’re helping your team spend less time navigating and more time securing.

See It In Action

Efficiency is the best defense. By aligning related capabilities under unified domains, Upwind reduces the cognitive load on your team, allowing you to move from detection to remediation in record time. These navigation improvements ensure that your most critical data—identities, secrets, and vulnerabilities—is always just one click away.

If you’d like to see how this feature fits into your environment – or to explore how Upwind can help you prioritize and remediate risk more effectively – schedule a customized demo with us. We’ll walk through your use cases, integrations, and security goals to show how Upwind delivers actionable cloud security at scale.

Contents

Further Reading

You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Yuval_ArgoCD Research

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover 

Executive Summary  This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS