Prowler reposted this
Prowler winner of the Black Hat Asia Startup competition!! Thankful for our amazing community, customers and employees!! See you in Vegas!! 🚀🚀🚀
Prowler is the most comprehensive Open Source platform for cloud security. It is trusted by orgs of all sizes, and used everyday so teams can be confident in their cloud security. Sign up or download it free or today for: • Dashboards with actionable, direct insights for every level of detail of your security posture • Holistic view of your cloud infrastructure • Results in seconds
External link for Prowler
Prowler reposted this
Deterministic Cloud security is key to put Agentic Cloud Security in practice like a pro, Prowler Hub (hub.prowler.com) is the center of the AI infra and Cloud security infra universe, already used by Cloude Code, Codex, Cursor, Windsurf when you ask to do Cloud security related tasks. Aaaaand... its next version will be a jawbreaker... also with a new name, a new Prowler product.
Prowler reposted this
What two days ahead here at Black Hat Asia, tomorrow we present all new features just released at the Arsenal (10AM local time) and Friday I'll be presenting twice, one at the Business Hall Theatre 1 "Prowler: From Deterministic to Al-Driven Cloud Security" at 11:35AM. And after that, the Startup Spotlight FINAL! 5 minutes, including a demo on "Prowler, the Agentic Cloud Defender" 🤠 I will be most of the time at the Business Hall Startup City (SC10) doing more demos! #OpenCloudSecurity
Prowler reposted this
A month ago I started working into support Vercel as one of our Cloud Providers in Prowler with the help of José Daniel Barranquero Ortigosa and Andoni 🖖 Alonso Fernández it’s already available. Take advantage of these 26 checks because things are getting crazy, protect yourself! These and numerous other Cloud Providers are available on our platform. https://prowler.com
Vercel confirmed a security incident today. A threat actor claiming to be ShinyHunters is allegedly selling access keys, source code, database data, NPM and GitHub tokens on BreachForums. Vercel’s own bulletin is clear: review and rotate environment variables, and use the sensitive environment variables feature. The problem: in teams with dozens of projects and hundreds of variables, that review is done manually. And when there’s pressure, it’s done poorly. At Prowler we have an official Vercel provider. After reading the bulletin, here’s what I’d check with a scan right now: 🔴 Projects without WAF enabled 🔴 Deployments without password protection or Vercel Authentication 🔴 Team settings, domains and API token configuration 26 checks across your Vercel tenant. Connects via a Vercel Access Token, no agents, no installations. And if the leaked GitHub tokens turn out to be real, the blast radius doesn’t stop at Vercel and rotating keys. Prowler’s GitHub provider also lets you review branch protection on critical repos, org-wide MFA, secret scanning, and GitHub Actions permissions. Two providers, one audit. You can’t prevent the breach, Vercel can. But shrinking your exposure surface while the scope is being clarified, that’s on you. Links in the first comment 👇 #CloudSecurity #Vercel #Prowler
Prowler reposted this
🔊 We are so glad to announce we got to the final of the Black Hat Asia Startup Spotlight! 🥳 if you are around in Singapore next week, come to see us in action at the Arsenal, our booth and the Startup Spotlight final pitch! More info at https://lnkd.in/g3w_72wW
Prowler reposted this
Back in San Francisco one more year for BSidesSF and #RSAConference2026 🇺🇸 Every time I come here I feel the same kind of energy… but this year something is clearly changAIng… For many years, cloud security has been mostly deterministic. We write open source rules, we check configurations, we generate findings. This has worked well, and it is still the foundation of everything we do. Now we are entering a different phase. Cloud is more than ever before ephemeral, dynamic with AI services and AI generated workloads (launch whatever that seems to work to the cloud). Static checks alone are not enough anymore. We need systems that can understand context, reduce noise, and help us prioritize what really matters. AI is not replacing deterministic security, moreover it is augmenting it. The future and the present is combining both: - deterministic checks for precision and trust bc the open source foundation we lead (see hub.prowler.com) - AI for context, prioritization and speed but also to extend capabilities and relationships between resources, cloud providers and human identities. This is something we are exploring deeply at Prowler, building the new generation of cloud security that is not only about finding issues (before at code, during at runtime and after an incident), but about helping teams act on them at any time. Curious to hear what do you think about this. #CloudSecurity #AI #Prowler #BSidesSF #RSAConference
Prowler reposted this
Sometimes the right solution is the one that, at first glance, seems like the worst possible idea. At Prowler, we wanted to add the Microsoft 365 provider with full coverage, but we quickly hit a wall. The Microsoft Graph API wouldn’t even cover 10% of the CIS Microsoft 365 Foundations Benchmark. Not covering it wasn’t an option. After exploring different approaches, we ended up doing something that sounds… questionable: Executing PowerShell from Python. Yes, you read that right. It doesn’t sound like something you’d take to production. But we did. We built a full PowerShell wrapper in Python to make it work: secure execution, consistent behavior, authentication, memory management… basically making two worlds work together that were never meant to. And in the end, it worked. We reached the coverage we needed and made it behave like any other provider in Prowler. We open sourced it as a standalone tool so others don’t have to go through the same journey. Full story in the blog below. 🔗 Blog Post: https://lnkd.in/e46bh2rp 🔗 Repo: https://lnkd.in/eHh4zeSc
Prowler reposted this
🚀 RELEASE ALERT! 🚀 and yes! it comes with more AI 😉 👉 While celebrating our participation at the RootedCON in Madrid this week, we release Prowler 5.19 with important annoncements and some features only available in Prowler Cloud (our paid service), all details below and at https://lnkd.in/egegP8sx: - 🏛️ AWS Organizations Onboarding: secure your entire AWS Org with Prowler in seconds. (Prowler Cloud and Prowler Cloud Enterprise only) - 📤 Import Findings: import any Prowler finding in OCSF to Prowler Cloud from the Prowler CLI, Github Action, Jenkins, etc. Easy integration with your cloud development and deployment workflow. (Prowler Cloud and Prowler Cloud Enterprise only) - ☁️ OpenStack is now supported with Multi-Region & New Services! See all details in https://lnkd.in/eeTSVFyK - 🐳 Container Image Scanning! Yes, now you can do that (and infra as code too!) with Prowler, we have embeded Trivy to give you the most from a single platform :D - 🏢 Google Workspace Provider - CLI: as we want to help you on any important cloud, now we have support for Google Workspace. Now we have most popular SaaS for collaboration, M365 and Google Workspace! - ☁️ Cloudflare: Now with full support in CLI, API and WebUI, - 🕸️ Attack Paths: Major Upgrades to give you more comprehensive and helpful information. - 🤖 Attack Paths in Prowler MCP Server: that means our AI can give you even more information and correlate it! - 📚 New Compliance Frameworks: CSA CCM 4.0, CIS 6.0 for AWS, SecNumCloud for AWS. - 🔍 New Checks, dozens of new checks across many supported cloud providers. - Soon!! Vercel support, it is already in the repo :D - 🤖 Take advantage of our AI to make the most from Prowler and create remediation plans, presentations for your CISO, code to fix it all, and more.
Prowler reposted this
🎶 Cloud Village is hitting BSidesSF with a cloud-powered CTF! Huge thanks to our sponsors: Amazon Web Services (AWS), Varonis, TrendAI, Aikido Security, and Prowler 🤘☁️ Real-world attack paths. Hands-on skills. Bring your best riffs. 🎸🚩 🔗 https://lnkd.in/eZR7W5R9
LinkedIn is better on the app
Don’t have the app? Get it in the Microsoft Store.
Open the app