Cloud computing security
25
MENTIONS
10
EPISODES
10
PODCASTS
Search complete. 25 mentions across 10 episodes found for "Cloud computing security".
Sep 15, 2026
Mitiga Mic. Cloud Security Is Broken - What's Next? Ulf Lindqvist, SRI International & Bill Crowell.
B
12:23Brian ContosHOST
So you really do need to focus on that resiliency, that ability to detect nefarious activity and respond to it quickly.
B
12:30Brian ContosHOST
Do you think that's kind of leading the charge now, detection and response, when it comes to cloud security?
B
12:35Bill CrowellGUEST
No, I think that's right.
B
12:37Bill CrowellGUEST
And that's one of the reasons that the whole zero trust for the cloud approach is important because it allows you to contain, if you will, micro segment the cloud.
#255 - Gemini 3.7, Jalapeño, Qwen 3.8, Drones
A
31:32Andrey KurenkovHOST
And sticking with Anthropic, next, bringing the cybersecurity capabilities of Cloud Mythos 5 to more defenders.
A
31:39Andrey KurenkovHOST
So Mythos 5 is now available in Cloud Security for enterprise customers, enabling code-based vulnerability scanning with suggested patches billed as standard token security.
A
31:52Andrey KurenkovHOST
This is expanding from a prior program where we had Project Glasswing.
A
31:59Andrey KurenkovHOST
They partnered with some limited organizations.
Building an AI Native Enterprise with Francis Brero
F
27:31Francis BreroGUEST
But then there are things where, you know, when the new capabilities for generating images came out, it changed the way we thought about how do we generate images in marketing.
F
27:42Francis BreroGUEST
Like when Midjourney came out, it changed, like, how do we think about doing Dex? Like Gamma came out, then like Cloud Design came out, and then we have Cloud Security.
F
27:50Francis BreroGUEST
And so we have people in these teams that are testing those and like kind of being the trailblazers to determine, does this fit in any problem that we have as an organization? And then we roll it out to the rest of the team.
F
28:03Francis BreroGUEST
The truth of it is the majority of the releases are not that relevant to the team.
Episode 202: Delineating AI Security and Cybersecurity
R
17:01Rob T. LeeGUEST
And I use that TSA analogy here is 'cause you would theoretically be able to do a lot more damage, you know, even, um...
R
17:07Rob T. LeeGUEST
Ed, I'm not sure if you saw some of the output from Jason Clinton's talk just from our own summit a couple days ago at Cloud Security, is that he said we're only months away from a teenager having the literal capabilities of a nation state attacker from their basement.
R
17:21Rob T. LeeGUEST
When you have that amount of lethality and the only thing that was holding back nation state attacks was the fact that they didn't know when it would go kinetic, meaning that if we did this, would we actually have, you know, something hit us physically.
S
17:33Sean AtkinsonHOST
Yeah.
9 MINS LATER
R
26:07Rob T. LeeGUEST
And then you'll start to see, okay, all the different configuration things that you actually had to put in place, you know.
R
26:12Rob T. LeeGUEST
But not enough people in cybersecurity are doing that.
R
26:14Rob T. LeeGUEST
How many people in cloud security actually built a cloud cluster that they managed? This is, again, something I see, you know, the rudimentary skills in some cases.
R
26:23Rob T. LeeGUEST
You're asked to defend a thing you actually never built.
Episode 202: Delineating AI Security and Cybersecurity
R
17:01Rob T. LeeGUEST
And I use that TSA analogy here is 'cause you would theoretically be able to do a lot more damage, you know, even, um...
R
17:07Rob T. LeeGUEST
Ed, I'm not sure if you saw some of the output from Jason Clinton's talk just from our own summit a couple days ago at Cloud Security, is that he said we're only months away from a teenager having the literal capabilities of a nation state attacker from their basement.
R
17:21Rob T. LeeGUEST
When you have that amount of lethality, and the only thing that was holding back nation state attacks was the fact that they didn't know when it would go kinetic, meaning that if we did this, would we actually have, you know, something hit us physically.
S
17:33Sean AtkinsonHOST
Yeah.
9 MINS LATER
R
26:07Rob T. LeeGUEST
And then you'll start to see, okay, all the different configuration things that you actually had to put in place, you know.
R
26:12Rob T. LeeGUEST
But not enough people in cybersecurity are doing that.
R
26:14Rob T. LeeGUEST
How many people in cloud security actually built a cloud cluster that they managed? This is, again, something I see, you know, the rudimentary skills in some cases.
R
26:23Rob T. LeeGUEST
You're asked to defend a thing you actually never built.
Security Now 1093: Tokens in the Stream
S
31:19Steve GibsonHOST
They're trying to manage... mythos fives power so that it's used for good only for good so what's interesting is the way they did this uh their posting said We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense.
S
31:41Steve GibsonHOST
Cloud Mythos 5 is now available in cloud security and coming soon to partners cyber defense tools.
S
31:50Steve GibsonHOST
We're also launching a $35 million fund to help secure open source software and sharing plans to expand our cyber verification program.
S
32:02Steve GibsonHOST
And then now they're going to break all that down.
8 MINS LATER
S
40:14Steve GibsonHOST
There's no way it could be abused.
S
40:16Steve GibsonHOST
So anyway, that's beginning to happen.
S
40:19Steve GibsonHOST
Okay, so next up is making cloud security available with Mythos 5 for enterprise customers.
S
40:27Steve GibsonHOST
They write, starting today, cloud security scan, when today mean last Friday, cloud security scans now run on cloud Mythos 5.
The AI Moat Is Shrinking—and the Economics of Agents Are Changing
S
2:04speaker_0HOST
Anthropic is applying that capability to security.
S
2:08speaker_0HOST
Cloud Mythos 5 is available for code scanning through Cloud Security, with direct user prompting restricted.
S
2:15speaker_0HOST
The scans trace repository data flows, identify weaknesses, assign CWB labels, and suggest patches.
S
2:23speaker_0HOST
Public beta access is available to cloud enterprise customers.
P
Unknown podcast
Supply Chain Security Feeds on the Shared Responsibility Model
Aug 20 · 3 Mentions
L
0:01LucasHOST
So Luna, you know that moment when you realize the thing you thought was someone else's job is actually yours? That's been happening a lot in cloud security lately.
L
0:10LucasHOST
And it's the reason we're seeing a wave of CISOs renegotiating their cloud contracts.
L
0:16LunaHOST
I've heard that term, shared responsibility model, but I bet a lot of our listeners think their cloud provider is handling all the security.
L
2:08LunaHOST
And more chances for misconfiguration, right? I remember reading that something like 80% of cloud breaches are due to customer misconfiguration.
L
2:18LucasHOST
that number keeps popping up.
L
2:20LucasHOST
And it's why we're seeing a new role emerge, the cloud security architect, someone who specifically understands the shared responsibility model across different providers and can map out where the gaps are.
L
2:33LunaHOST
So what does a cloud security architect actually do differently from a traditional security engineer?
L
2:40LucasHOST
They're the ones who sit down with the DevOps teams and say, this serverless function you're deploying, who's responsible for patching the runtime? Not the provider.
Thomas Richard talks to Jeff Bailey, Director, IT and Information Security, Apptegy
T
18:38Thomas RichardHOST
Yeah.
J
18:39Jeff BaileyGUEST
I, my main background, I spent a few years in cloud security.
J
18:42Jeff BaileyGUEST
It's like, I may know a little about cloud security, but there's always that issue as a manager, it's just like as soon as I give my opinion on anything, that becomes the answer and that becomes the default.
J
18:53Jeff BaileyGUEST
So you wanna make sure, like, I wanna make sure if I ever say something, I want my team to always be able to challenge me, especially the, like, the folks that we hired to be the experts in their field.
J
19:03Jeff BaileyGUEST
If I say something about application security, I want my application security engineer to go, "Jeff, that's not a very good idea." And I want him to say that on a call with other stakeholders.
J
21:47Jeff BaileyGUEST
Yeah, absolutely.
J
21:48Jeff BaileyGUEST
Just like a whole, kinda like a paradigm shift.
J
21:50Jeff BaileyGUEST
When I moved from doing the SOC endpoint and went into the security engineering, kind of the cloud security, it was just like, "Oh, the, the biggest risk is a misconfiguration.
Tearing Down Vendor Fluff: The Real State of AI Security | James Berthoty
J
0:00James BerthotyGUEST
I was very close to the cloud security adoption early on.
J
0:03James BerthotyGUEST
And what surprised me about AI is it's much more of like a executive push from day one than cloud was.
J
0:09James BerthotyGUEST
But there's like this mandate from a lot of executive teams to where if you're not adopting AI, you're like a dead company.
M
0:15Mackenzie JacksonHOST
It's no secret that in security, every single vendor is going to tell you that they solve all your problems.
M
0:20Mackenzie JacksonHOST
When you cut through the marketing noise, the acronym soup and the vendor fluff, what actually stops a breach? Today, I'm joined by James Bathouti, a cloud security engineer and FedRAMP survivor who became an analyst and built Latio, a practitioner-first analyst firm tearing down vendor BS.
M
0:35Mackenzie JacksonHOST
I brought on James to cut straight to the truth.
M
0:38Mackenzie JacksonHOST
What's actually winning in security during the AI revolution? And is it finally time that we throw away our traditional sass and SCA scanners.
M
1:51Mackenzie JacksonHOST
I really liked the journey of kind of how you, how you got there because I think it probably provides a lot of credibility as to like what, like, you know, not, not there's anything wrong with the analyst industry, right? We all love Gartner.