Evento di Lancio: Smart AI Security. Controllo Totale dei Dati. Prenota il tuo posto

chiudere
chiudere
La tua rete di domani
La tua rete di domani
Pianifica il tuo percorso verso una rete più veloce, sicura e resiliente, progettata per le applicazioni e gli utenti che supporti.
Experience Netskope
Prova direttamente la piattaforma Netskope
Ecco la tua occasione per sperimentare in prima persona la piattaforma single-cloud di Netskope One. Iscriviti a laboratori pratici e a ritmo autonomo, unisciti a noi per dimostrazioni mensili di prodotti dal vivo, fai un test drive gratuito di Netskope Private Access o partecipa a workshop dal vivo guidati da istruttori.
Un leader in SSE. Ora è un leader nel settore SASE a singolo fornitore.
Netskope è riconosciuto come Leader Più Lontano in Visione sia per le piattaforme SSE che SASE
2 volte leader nel Quadrante Magico di Gartner® per piattaforme SASE
Una piattaforma unificata costruita per il tuo percorso
Securing Generative AI for Dummies
Securing Generative AI for Dummies
Scopri come la tua organizzazione può bilanciare il potenziale innovativo dell'AI generativa con pratiche solide di sicurezza dei dati.
eBook sulla Modern Data Loss Prevention (DLP) for Dummies
Modern Data Loss Prevention (DLP) for Dummies
Ricevi consigli e trucchi per passare a un DLP fornito dal cloud.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Smettila di inseguire la tua architettura di rete
Comprendere dove risiede il rischio
Advanced Analytics trasforma il modo in cui i team di operazioni di sicurezza applicano insight basati sui dati per implementare policy migliori. Con l'Advanced Analytics, puoi identificare tendenze, concentrarti sulle aree di interesse e utilizzare i dati per agire.
Supporto tecnico Netskope
Supporto tecnico Netskope
I nostri ingegneri di supporto qualificati sono dislocati in tutto il mondo e possiedono competenze diversificate in sicurezza cloud, networking, virtualizzazione, content delivery e sviluppo software, garantendo un'assistenza tecnica tempestiva e di qualità.
Video Netskope
Formazione Netskope
La formazione Netskope ti aiuterà a diventare un esperto di sicurezza cloud. Siamo qui per aiutarti a proteggere il tuo percorso di trasformazione digitale e a sfruttare al meglio le tue applicazioni cloud, web e private.

Cloud Threats Memo: Staggering Statistics About Recent Cloud Misconfigurations

May 06 2021

Cloud misconfigurations continue to be a serious concern for organizations, and the list of security incidents caused by the exposure of data from Saas and IaaS applications only continues to grow. If we just consider the last week of April, there have been three cases of popular services spilling sensitive data: an unsecured Azure Blob has led to the exposure of thousands of files containing product pitches, a popular online resource for paleo recipes and tips has leaked the customer records of 70,000 users (unsurprisingly from a misconfigured AWS S3 bucket), and finally, and this is the most serious incident, an employee’s mistake inadvertently exposed the test result data involving the health information of 164,000 individuals on GitHub (once again).

There are also alarming figures coming from two recent studies: according to a report published by the open-source security company Snyk, misconfigurations are not only the most common cloud-native security incidents (45%) but also the main concerns (58%) for the respondents. Similarly, a second report from Censys has identified nearly 2 million database instances and more than 1.9 million RDP services exposed across cloud providers. We have also observed the exposure of RDP and SSH services in public cloud workloads, but the real problem is that the criminals are also observing (and exploiting) the same trends. For example, recently Advintel observed that Ryuk ransomware attacks are increasingly relying on compromising exposed RDP connections to gain an initial foothold on a target network.

How Netskope mitigates the risk of misconfigurations in public cloud

Netskope Public Cloud Security detects misconfigurations on AWS, Azure, and GCP, preventing organizations from leaking data from publicly accessible buckets or blobs, and in general from leaving misconfigurations (such as open database ports) that can be exploited by the bad actors. A set of predefined profiles allows organizations to comply with best practices and industry standards such as NIST CSF, PCI-DSS, CIS. Additionally, it is possible to easily build custom rules with a Domain Specific Language.

Netskope Next Gen SWG provides granular control for GitHub (and thousands of additional cloud applications) in terms of adaptive access control, DLP, and threat protection, preventing the upload of PHI by an employee via one of the predefined DLP profiles. Additional controls are available via the API protection in the CASB module. For example, an organization can be alerted if a repository is made public. 

Netskope Private Access publishes resources (including RDP and SSH servers) in a simple and secure manner embracing the Zero Trust paradigm. It is possible to publish and segment resources located in a local data center, but also in a private or public cloud. The published service is not directly visible, and a security posture check is performed before the access is granted, mitigating the risk of brute-force or password-spraying attacks, a common way for malicious actors to exploit exposed services to break into organizations.

Stay safe!

author image
Paolo Passeri
Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
Connettiti con Netskope

Iscriviti al blog di Netskope

Iscriviti per ricevere ogni mese una panoramica degli ultimi contenuti di Netskope direttamente nella tua casella di posta.