Feed
Upwind Feed
Feed
Grid

What I’ve Learned Building a Technology Partner Ecosystem
Reaching 100+ integrations with The Lineup at Upwind is a milestone I’m incredibly proud of. But when I think about what it took to get here, the number itself isn’t the most interesting part. The interesting part is what happens along the way. You start by building integrations. Then customers introduce new use cases. Partners…

Agent Skill Risks: Taxonomy 101
Introduction In the first eight months of 2026, a Russian-speaking threat actor who had built a career on hotel-booking and fintech platforms turned to AI companies. The technique they used against one AI vendor did not involve any exploit. Like most AI vendors, the target ran an automated evaluation sandbox, an agent pipeline that reads…

Upwind Now Secures Snowflake from AI Down to the Storage Underneath It
Ask a security team where the company's most sensitive data lives and they'll say Snowflake without pausing. Ask who can reach it and the room goes quiet, because that answer belongs to the data team. It isn't negligence, it's vocabulary. Snowflake speaks in roles, grants, warehouses and schemas. Your cloud security program speaks in IAM,…

What IAM Sees That You Don’t
Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…

Let Me Speak to Your Manager (Account)
The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…

Introducing the new Configurations experience in Upwind
Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys
In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…

Show Me the Context: Building the Full Request Context for AWS IAM
This post was written in early August 2026, ahead of our fwd:cloudsec Europe talk. On August 25, AWS launched the Access Troubleshooter (currently in public preview), a first-party feature that surfaces the request context for denied requests. We've updated this post to account for it. When the IAM engine evaluates your request, it matches your…

Building the Future: Introducing the Upwind AI Security Lab
I have always been fascinated by what comes next. Growing up, I watched technology reinvent itself again and again, from early gaming and the dot-com era to SaaS, cloud, and modern software development. I remember wondering when I would get the chance to help build what came next. At the time, I was mostly watching…

5 Back to School Security Predictions: The Attacker Class Average Just Moved
Back to school season is here, which makes this a good moment to look at what changed in the threat landscape over the summer. AI-assisted attackers haven't climbed toward the top of the field so much as filled in the middle of it and the middle is the population almost no security program was designed…

The Org Chart is The Wrong Security Boundary
The department model of dividing companies into groups earned its place. Finance gets the finance applications, engineering gets the repositories, HR gets the HRIS, and the boundaries hold because software was bought per function and used per function. Identity and access management platforms, such as Active Directory and Okta, were built around exactly that. Groups…

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part III
Recap In Part I and Part II, we: Networking and VPC Mode Network Isolation Testing The microVM is assigned an IPv6 address matching the value in the JWT. Across multiple runs, all addresses shared the same 2600:1f18::/32 prefix, but cross-microVM communication always failed. We attempted to reach the host EC2 IMDS by manipulating the route…
What I’ve Learned Building a Technology Partner Ecosystem
Reaching 100+ integrations with The Lineup at Upwind is a milestone I’m incredibly proud of. But when I think about what it took to get here, the number itself isn’t the most interesting part. The interesting part is what happens along the way. You start by building integrations. Then customers introduce new use cases. Partners…

Latest

October 6, 2026
Agent Skill Risks: Taxonomy 101
Introduction In the first eight months of 2026, a Russian-speaking threat actor who had built a career on hotel-booking and fintech platforms turned to AI companies. The technique they used against one AI vendor did not involve any exploit. Like most AI vendors, the target ran an automated evaluation sandbox, an agent pipeline that reads…

October 1, 2026
Upwind Now Secures Snowflake from AI Down to the Storage Underneath It
Ask a security team where the company's most sensitive data lives and they'll say Snowflake without pausing. Ask who can reach it and the room goes quiet, because that answer belongs to the data team. It isn't negligence, it's vocabulary. Snowflake speaks in roles, grants, warehouses and schemas. Your cloud security program speaks in IAM,…

September 25, 2026
What IAM Sees That You Don’t
Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…

September 25, 2026
Let Me Speak to Your Manager (Account)
The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…

September 24, 2026
Introducing the new Configurations experience in Upwind
Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…

September 23, 2026
What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys
In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…

September 23, 2026
Show Me the Context: Building the Full Request Context for AWS IAM
This post was written in early August 2026, ahead of our fwd:cloudsec Europe talk. On August 25, AWS launched the Access Troubleshooter (currently in public preview), a first-party feature that surfaces the request context for denied requests. We've updated this post to account for it. When the IAM engine evaluates your request, it matches your…

September 23, 2026
Building the Future: Introducing the Upwind AI Security Lab
I have always been fascinated by what comes next. Growing up, I watched technology reinvent itself again and again, from early gaming and the dot-com era to SaaS, cloud, and modern software development. I remember wondering when I would get the chance to help build what came next. At the time, I was mostly watching…

September 22, 2026
5 Back to School Security Predictions: The Attacker Class Average Just Moved
Back to school season is here, which makes this a good moment to look at what changed in the threat landscape over the summer. AI-assisted attackers haven't climbed toward the top of the field so much as filled in the middle of it and the middle is the population almost no security program was designed…

September 21, 2026
The Org Chart is The Wrong Security Boundary
The department model of dividing companies into groups earned its place. Finance gets the finance applications, engineering gets the repositories, HR gets the HRIS, and the boundaries hold because software was bought per function and used per function. Identity and access management platforms, such as Active Directory and Okta, were built around exactly that. Groups…

September 16, 2026
What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part III
Recap In Part I and Part II, we: Networking and VPC Mode Network Isolation Testing The microVM is assigned an IPv6 address matching the value in the JWT. Across multiple runs, all addresses shared the same 2600:1f18::/32 prefix, but cross-microVM communication always failed. We attempted to reach the host EC2 IMDS by manipulating the route…

September 15, 2026
What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part II
Recap In Part I, we explored the AgentCore Runtime microVM from the inside and discovered we weren't alone - four platform binaries were running alongside our code, and one of them was quietly shipping logs to an AWS-internal S3 bucket. We left off with a question: what can we learn from these internal components, and…