RSS for Slack
Research

Critical RCE Vulnerability in jsonpath-plus (CVE-2024-21534)

A critical Remote Code Execution (RCE) vulnerability identified as CVE-2024-21534 has been discovered in versions of the jsonpath-plus package before 10.0.0. This vulnerability allows attackers to execute arbitrary code on affected systems by exploiting improper input sanitization and the unsafe default usage of the vm module in Node.js. jsonpath-plus is a JavaScript implementation of JSONPath […]

Product

Automatically Secure AWS Lambda Functions with Upwind

We are excited to announce support for AWS Lambda as a part of Upwind’s agentless Cloud Scanners. Upwind’s protection for Lambda functions running on AWS can be seen throughout the Upwind platform, extending our proactive risk analysis and visibility across  your entire cloud infrastructure – from containers to VMs to serverless. What are Lambda Functions? […]

Company News

Upwind’s Record-Breaking Sensor Scans 30GB Container Images Using Only 3% of its Image Size

Upwind’s eBPF sensor is lightweight and high performance, which was recently shown in a record-breaking image scan with customer H2O.ai. When scanning H2O.ai’s 30GB container image with multiple dependencies, the Upwind sensor consumed less than 1GB of RAM, about 3% of the image size, demonstrating how Upwind ensures comprehensive runtime security coverage with a lightweight […]

Product

Upwind’s Comprehensive Protection for AWS ECS Fargate Resources

The Upwind platform includes comprehensive protection for cloud infrastructure and applications, including Amazon Elastic Container Service (ECS) Fargate.  AWS Fargate has numerous advantages, but it also presents unique cloud security challenges, which Upwind actively solves with real-time monitoring and protection. In this article, we will cover the basic anatomy of AWS Fargate, challenges that make […]

Product

Seamlessly Protect Infrastructure and Applications on Microsoft Azure with Upwind

The Upwind Cloud Security Platform provides comprehensive protection for infrastructure and applications across any cloud environments, including Microsoft Azure.  This includes protection for Azure assets, infrastructure and applications within  every capability  of the Upwind platform, including: “Upwind seamlessly protects our Azure environment, making it easy to understand our most critical cloud security posture findings, automatically […]

Research

Analyzing the Latest CUPS RCE Vulnerability: Threats and Mitigations

Remote Code Execution (RCE) in CUPS via ‘cups-browsed’ CUPS (Common Unix Printing System) is a popular printing system for Unix-like systems, with cups-browsed responsible for printer discovery and network browsing. A recent vulnerability in cups-browsed allows Remote Code Execution (RCE) through manipulated printer discovery responses. This vulnerability is caused by insufficient input validation on UDP […]

Research

Critical 9.9 Linux Bug Exposes Containers, Hosts and Endpoints to Remote Code Execution (RCE) Exploits

Several critical Linux vulnerabilities have been declared, involving a bug in CUPS, the Common UNIX Printing System. All versions of Red Hat Enterprise Linux (RHEL) are among the Linux distributions affected, but not in default configuration.  There are four vulnerabilities that have been identified and allocated the following CVEs – CVE-2024-47076, CVE-2024-47175, CVE-2024-47176 and CVE-2024-47177. […]

Add the Upwind RSS Feed to Slack

Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.