Skip to main content
Cloud computing security

Cloud computing security

Search complete. 25 mentions across 10 episodes found for "Cloud computing security".

Sep 15, 2026

Brian ContosHOST
12:23
So you really do need to focus on that resiliency, that ability to detect nefarious activity and respond to it quickly.
Brian ContosHOST
12:30
Do you think that's kind of leading the charge now, detection and response, when it comes to cloud security?
Bill CrowellGUEST
12:35
No, I think that's right.
Bill CrowellGUEST
12:37
And that's one of the reasons that the whole zero trust for the cloud approach is important because it allows you to contain, if you will, micro segment the cloud.
Andrey KurenkovHOST
31:32
And sticking with Anthropic, next, bringing the cybersecurity capabilities of Cloud Mythos 5 to more defenders.
Andrey KurenkovHOST
31:39
So Mythos 5 is now available in Cloud Security for enterprise customers, enabling code-based vulnerability scanning with suggested patches billed as standard token security.
Andrey KurenkovHOST
31:52
This is expanding from a prior program where we had Project Glasswing.
Andrey KurenkovHOST
31:59
They partnered with some limited organizations.
Francis BreroGUEST
27:31
But then there are things where, you know, when the new capabilities for generating images came out, it changed the way we thought about how do we generate images in marketing.
Francis BreroGUEST
27:42
Like when Midjourney came out, it changed, like, how do we think about doing Dex? Like Gamma came out, then like Cloud Design came out, and then we have Cloud Security.
Francis BreroGUEST
27:50
And so we have people in these teams that are testing those and like kind of being the trailblazers to determine, does this fit in any problem that we have as an organization? And then we roll it out to the rest of the team.
Francis BreroGUEST
28:03
The truth of it is the majority of the releases are not that relevant to the team.
Rob T. LeeGUEST
17:01
And I use that TSA analogy here is 'cause you would theoretically be able to do a lot more damage, you know, even, um...
Rob T. LeeGUEST
17:07
Ed, I'm not sure if you saw some of the output from Jason Clinton's talk just from our own summit a couple days ago at Cloud Security, is that he said we're only months away from a teenager having the literal capabilities of a nation state attacker from their basement.
Rob T. LeeGUEST
17:21
When you have that amount of lethality and the only thing that was holding back nation state attacks was the fact that they didn't know when it would go kinetic, meaning that if we did this, would we actually have, you know, something hit us physically.
Sean AtkinsonHOST
17:33
Yeah.

9 MINS LATER

Rob T. LeeGUEST
26:07
And then you'll start to see, okay, all the different configuration things that you actually had to put in place, you know.
Rob T. LeeGUEST
26:12
But not enough people in cybersecurity are doing that.
Rob T. LeeGUEST
26:14
How many people in cloud security actually built a cloud cluster that they managed? This is, again, something I see, you know, the rudimentary skills in some cases.
Rob T. LeeGUEST
26:23
You're asked to defend a thing you actually never built.
Rob T. LeeGUEST
17:01
And I use that TSA analogy here is 'cause you would theoretically be able to do a lot more damage, you know, even, um...
Rob T. LeeGUEST
17:07
Ed, I'm not sure if you saw some of the output from Jason Clinton's talk just from our own summit a couple days ago at Cloud Security, is that he said we're only months away from a teenager having the literal capabilities of a nation state attacker from their basement.
Rob T. LeeGUEST
17:21
When you have that amount of lethality, and the only thing that was holding back nation state attacks was the fact that they didn't know when it would go kinetic, meaning that if we did this, would we actually have, you know, something hit us physically.
Sean AtkinsonHOST
17:33
Yeah.

9 MINS LATER

Rob T. LeeGUEST
26:07
And then you'll start to see, okay, all the different configuration things that you actually had to put in place, you know.
Rob T. LeeGUEST
26:12
But not enough people in cybersecurity are doing that.
Rob T. LeeGUEST
26:14
How many people in cloud security actually built a cloud cluster that they managed? This is, again, something I see, you know, the rudimentary skills in some cases.
Rob T. LeeGUEST
26:23
You're asked to defend a thing you actually never built.
Steve GibsonHOST
31:19
They're trying to manage... mythos fives power so that it's used for good only for good so what's interesting is the way they did this uh their posting said We're sharing an update on our efforts to help more teams use frontier capabilities for cyber defense.
Steve GibsonHOST
31:41
Cloud Mythos 5 is now available in cloud security and coming soon to partners cyber defense tools.
Steve GibsonHOST
31:50
We're also launching a $35 million fund to help secure open source software and sharing plans to expand our cyber verification program.
Steve GibsonHOST
32:02
And then now they're going to break all that down.

8 MINS LATER

Steve GibsonHOST
40:14
There's no way it could be abused.
Steve GibsonHOST
40:16
So anyway, that's beginning to happen.
Steve GibsonHOST
40:19
Okay, so next up is making cloud security available with Mythos 5 for enterprise customers.
Steve GibsonHOST
40:27
They write, starting today, cloud security scan, when today mean last Friday, cloud security scans now run on cloud Mythos 5.
speaker_0HOST
2:04
Anthropic is applying that capability to security.
speaker_0HOST
2:08
Cloud Mythos 5 is available for code scanning through Cloud Security, with direct user prompting restricted.
speaker_0HOST
2:15
The scans trace repository data flows, identify weaknesses, assign CWB labels, and suggest patches.
speaker_0HOST
2:23
Public beta access is available to cloud enterprise customers.

Unknown podcast

Supply Chain Security Feeds on the Shared Responsibility Model

Aug 20 · 3 Mentions

LucasHOST
0:01
So Luna, you know that moment when you realize the thing you thought was someone else's job is actually yours? That's been happening a lot in cloud security lately.
LucasHOST
0:10
And it's the reason we're seeing a wave of CISOs renegotiating their cloud contracts.
LunaHOST
0:16
I've heard that term, shared responsibility model, but I bet a lot of our listeners think their cloud provider is handling all the security.
LunaHOST
2:08
And more chances for misconfiguration, right? I remember reading that something like 80% of cloud breaches are due to customer misconfiguration.
LucasHOST
2:18
that number keeps popping up.
LucasHOST
2:20
And it's why we're seeing a new role emerge, the cloud security architect, someone who specifically understands the shared responsibility model across different providers and can map out where the gaps are.
LunaHOST
2:33
So what does a cloud security architect actually do differently from a traditional security engineer?
LucasHOST
2:40
They're the ones who sit down with the DevOps teams and say, this serverless function you're deploying, who's responsible for patching the runtime? Not the provider.
Thomas RichardHOST
18:38
Yeah.
Jeff BaileyGUEST
18:39
I, my main background, I spent a few years in cloud security.
Jeff BaileyGUEST
18:42
It's like, I may know a little about cloud security, but there's always that issue as a manager, it's just like as soon as I give my opinion on anything, that becomes the answer and that becomes the default.
Jeff BaileyGUEST
18:53
So you wanna make sure, like, I wanna make sure if I ever say something, I want my team to always be able to challenge me, especially the, like, the folks that we hired to be the experts in their field.
Jeff BaileyGUEST
19:03
If I say something about application security, I want my application security engineer to go, "Jeff, that's not a very good idea." And I want him to say that on a call with other stakeholders.
Jeff BaileyGUEST
21:47
Yeah, absolutely.
Jeff BaileyGUEST
21:48
Just like a whole, kinda like a paradigm shift.
Jeff BaileyGUEST
21:50
When I moved from doing the SOC endpoint and went into the security engineering, kind of the cloud security, it was just like, "Oh, the, the biggest risk is a misconfiguration.
James BerthotyGUEST
0:00
I was very close to the cloud security adoption early on.
James BerthotyGUEST
0:03
And what surprised me about AI is it's much more of like a executive push from day one than cloud was.
James BerthotyGUEST
0:09
But there's like this mandate from a lot of executive teams to where if you're not adopting AI, you're like a dead company.
Mackenzie JacksonHOST
0:15
It's no secret that in security, every single vendor is going to tell you that they solve all your problems.
Mackenzie JacksonHOST
0:20
When you cut through the marketing noise, the acronym soup and the vendor fluff, what actually stops a breach? Today, I'm joined by James Bathouti, a cloud security engineer and FedRAMP survivor who became an analyst and built Latio, a practitioner-first analyst firm tearing down vendor BS.
Mackenzie JacksonHOST
0:35
I brought on James to cut straight to the truth.
Mackenzie JacksonHOST
0:38
What's actually winning in security during the AI revolution? And is it finally time that we throw away our traditional sass and SCA scanners.
Mackenzie JacksonHOST
1:51
I really liked the journey of kind of how you, how you got there because I think it probably provides a lot of credibility as to like what, like, you know, not, not there's anything wrong with the analyst industry, right? We all love Gartner.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.