Screenshot of a software application showing the Inventory section. It lists package names, scores, vulnerabilities, impact factors, and related images. The interface is clean with a gradient background transitioning from blue to pink and orange.

Upwind’s SBOM Explorer – Your Weapon for the Next 0-day Attack

Denise Ashur November 28, 2023

Upwind’s SBOM Explorer – Your Weapon for the Next 0-day Attack

We are excited to announce a new feature – Upwind’s Packages Tab.

You can now view all of the packages in your environment and their dependencies in Upwind’s Packages Tab. This serves as an SBOM explorer, as it includes all packages (with or without vulnerabilities). With this capability, you can now search for all packages, including searching by framework, package manager, most used package and how many resources use each package.

This feature can be your key weapon for the next zero-day attack, allowing you to quickly identify package use within your environment and all package dependencies. 

Use the Packages Tab to understand your resource usage and gain deeper insights into your running packages within seconds, streamlining your posture management and giving you contextualized insights into how your resources are being used at runtime.

Contents

Further Reading

Upwind-Sentinel

Upwind for Microsoft Sentinel – Available on Marketplace and Security Store

Security teams should not have to switch between tools to understand what is happening across their cloud environments. That’s why we’re excited to announce that the Upwind solution for Microsoft Sentinel is now available through the Microsoft Marketplace and the Microsoft Security Store. The integration brings Upwind security data directly into Microsoft Sentinel, helping security…
You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS