![Computers Checking Compliance Boxes - podcast episode cover](/_next/image?url=https%3A%2F%2Fimg.transistor.fm%2FPolH1MJ9xbL84sh94kTVQcprjB985EqcdaNRLa2Lalw%2Frs%3Afill%3A3000%3A3000%3A1%2Fq%3A60%2FaHR0cHM6Ly9pbWct%2FdXBsb2FkLXByb2R1%2FY3Rpb24udHJhbnNp%2Fc3Rvci5mbS9lcGlz%2Fb2RlLzExNjQ0Mzkv%2FMTY3MzQ1ODQ5Mi1h%2FcnR3b3JrLmpwZw.jpg&w=640&q=75)
Episode description
This episode is sponsored in part by the Google for Startups Cloud Program
Links:
- CircleCI came out with a security alert urging you to rotate any secrets stored in CircleCI.
- Another bite at the craptastic LastPass breach response, this article parses their weak-sauce PR statement
- Over the holidays Slack had some private GitHub code repositories stolen.
- ACSESSED is another Azure vulnerability
- Amazon S3 Encrypts New Objects By Default
- Updated whitepaper available: AWS Security Incident Response Guide
- iamfast analyzes your application code to generate a least-privilege IAM policy.
- Wiz has come up with and open sourced PEACH, a tenant isolation framework for cloud applications.