close
close
Your Network of Tomorrow
Your Network of Tomorrow
Plan your path toward a faster, more secure, and more resilient network designed for the applications and users that you support.
          Experience Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            A Leader in SSE. Now a Leader in Single-Vendor SASE.
            A Leader in SSE. Now a Leader in Single-Vendor SASE.
            Netskope debuts as a Leader in the Gartner® Magic Quadrant™ for Single-Vendor SASE
              Securing Generative AI for Dummies
              Securing Generative AI for Dummies
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                Modern Data Loss Prevention (DLP) for Dummies
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Modern SD-WAN for SASE Dummies Book
                  Modern SD-WAN for SASE Dummies
                  Stop playing catch up with your networking architecture
                    Understanding where the risk lies
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        The 6 Most Compelling Use Cases for Complete Legacy VPN Replacement
                        The 6 Most Compelling Use Cases for Complete Legacy VPN Replacement
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          Colgate-Palmolive Safeguards its "Intellectual Property” with Smart and Adaptable Data Protection
                          Colgate-Palmolive Safeguards its "Intellectual Property” with Smart and Adaptable Data Protection
                            Netskope GovCloud
                            Netskope achieves FedRAMP High Authorization
                            Choose Netskope GovCloud to accelerate your agency’s transformation.
                              Let's Do Great Things Together
                              Netskope’s partner-centric go-to-market strategy enables our partners to maximize their growth and profitability while transforming enterprise security.
                                Netskope solutions
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Netskope Technical Support
                                  Netskope Technical Support
                                  Our qualified support engineers are located worldwide and have diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ensuring timely and quality technical assistance
                                    Netskope video
                                    Netskope Training
                                    Netskope training will help you become a cloud security expert. We are here to help you secure your digital transformation journey and make the most of your cloud, web, and private applications.

                                      Cloud Threats Memo: Manage Your Leaky Public Cloud Misconfigurations

                                      Oct 19 2021

                                      A new day, a new wave of S3 leaks…

                                      Cloud misconfigurations continue to be a major concern for organizations and a constant source of data leaks. A recent report by IBM has revealed that misconfigurations are behind two-thirds of cloud security incidents. In the latest example Thingiverse, a website dedicated to sharing user-created digital design files, has allegedly suffered a leak on a popular hacking forum of a 36GB backup file with 228,000 unique email addresses and other personally identifiable information such as IP addresses, usernames, physical addresses, and full names. And guess what? Unsurprisingly the data comes from an SQL backup stored on a misconfigured AWS S3 bucket and, even worse, it was apparently dumped for the first time on October 13, 2020. Despite sharing an update, Makerbot, Thingiverse’s parent company, has somehow downplayed the impact of the breach claiming that less than 500 real users have really been affected, this is yet another example of the consequences of cloud misconfigurations, and how quickly bad actors can exploit them.

                                      And it’s not the only one… In a separate incident, a  few days earlier, the same fate befell Plug and Play Ventures, a venture capital firm that runs a matchmaking service linking investors with startups. With a scary coincidence, the company exposed a 6GB PostgreSQL database (containing the personal information of the investors and the startup CEOs and more than 50,000 unique email addresses) from a misconfigured AWS S3 bucket, and even in this case, the data had been left unsecured for almost a year (October 20, 2020).

                                      These two examples show not only how common these misconfigurations might be (and how bad the consequences might be), but also how easily these security holes can go undetected for months (or years).

                                      How Netskope mitigates the risk of misconfigurations in public cloud

                                      Netskope Public Cloud Security detects misconfigurations on IaaS environments such as AWS, Azure, and Google Cloud Platform, preventing organizations from leaking data from publicly accessible buckets or blobs, and in general from leaving misconfigurations that can be exploited by the bad actors. A set of predefined profiles allows userrs to comply with best practices and industry standards such as NIST CSF, PCI-DSS, CIS. Additionally, it is possible to easily build custom rules with a Domain Specific Language. The same protection is also available for SaaS applications (such as Microsoft 365, Salesforce, GitHub, Zoom, and ServiceNow) thanks to the new SSPM (SaaS Security Posture Management) module.

                                      Netskope Private Access publishes resources (including RDP and SSH servers) in a simple and secure manner embracing the Zero Trust paradigm. It is possible to publish and segment resources located in a local data center, but also in a private or public cloud. The published service is not directly visible, and a security posture check is performed before the access is granted, mitigating the risk of brute-force or password-spraying attacks, a common way for malicious actors to exploit exposed services to break into organizations.

                                      Stay safe!

                                      author image
                                      Paolo Passeri
                                      Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
                                      Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.

                                      Stay informed!

                                      Subscribe for the latest from the Netskope Blog