Upwind’s Runtime Vulnerability Management
Contents
Further Reading

Agent Skill Risks: Taxonomy 101
Introduction In the first eight months of 2026, a Russian-speaking threat actor who had built a career on hotel-booking and fintech platforms turned to AI companies. The technique they used against one AI vendor did not involve any exploit. Like most AI vendors, the target ran an automated evaluation sandbox, an agent pipeline that reads…

Upwind Now Secures Snowflake from AI Down to the Storage Underneath It
Ask a security team where the company's most sensitive data lives and they'll say Snowflake without pausing. Ask who can reach it and the room goes quiet, because that answer belongs to the data team. It isn't negligence, it's vocabulary. Snowflake speaks in roles, grants, warehouses and schemas. Your cloud security program speaks in IAM,…

What IAM Sees That You Don’t
Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…