cloud-security

48 posts

cloudflare

Serving the most critical missions- Cloudflare for Government achieves FedRAMP Class D (High) Certified status (opens in new tab)

Cloudflare announced that Cloudflare for Government has achieved FedRAMP High (Class D) certification, enabling it to support highly sensitive federal workloads. The company is also using the systems built for FedRAMP High as the foundation for pursuing DoD Impact Level 4 authorization. Its core argument is that government agencies should receive the same modern capabilities as commercial customers without relying on isolated, outdated platforms. ## What FedRAMP High Represents - FedRAMP provides standardized security assessment, authorization, and continuous monitoring for U.S. government cloud services. - Cloudflare previously achieved FedRAMP Moderate authorization in 2022. - FedRAMP High involves substantially stricter controls and addresses data where a breach could have catastrophic consequences. - High-impact workloads include law enforcement, emergency services, financial systems, and national security information. - The authorization was sponsored by the National Institute of Standards and Technology and verified by the FedRAMP Program Management Office. ## One Platform on a Global Network - Traditional public-sector technology platforms often use separate, isolated environments that fall behind commercial products. - Cloudflare instead runs the same software stack across its global network. - Its FedRAMP High offering uses the same underlying machines and services, with software-defined regional controls rather than a separate government cloud. - This allows federal customers to access current Zero Trust tools, application performance services, and developer features as they are released. ## Data Localization and Compliance - Cloudflare’s Data Localization Suite controls where traffic is processed and stored. - For FedRAMP High services, traffic inspection and processing can be restricted exclusively to U.S. data centers. - These software-defined controls allow Cloudflare to meet strict residency and handling requirements while retaining a unified global architecture. ## Path Toward DoD IL4 - Cloudflare designed its FedRAMP High systems with DoD Impact Level 4 requirements in mind. - DoD IL4 applies to systems handling controlled, unclassified information. - The company expects its existing compliance infrastructure to support the pursuit of IL4 authorization. - Cloudflare argues that this approach could help defense organizations adopt new security capabilities faster than release-isolated government clouds allow. Cloudflare presents FedRAMP High as more than a compliance milestone: it is a way to modernize federal infrastructure with Zero Trust security, DDoS protection, resilient services, and continuously updated technology.

github

Investigating unauthorized access to GitHub-owned repositories (opens in new tab)

Alexis Wales is GitHub’s Chief Information Security Officer, responsible for protecting the platform, its products, and the open source community. With two decades of experience defending critical networks, she combines public- and private-sector expertise to address major cybersecurity challenges affecting modern technology. ## Leadership at GitHub - Leads a team of security professionals at GitHub. - Focuses on safeguarding GitHub’s platform and products. - Supports more than 150 million developers building and deploying software securely. - Helps protect the broader open source community. ## National Cybersecurity Experience - Has 20 years of experience defending critical national and private-sector networks. - Previously worked with the Department of Defense. - Served at the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). ## Public-Private Collaboration - Her government experience shaped a strong interest in cooperation between public and private organizations. - Advocates collaboration to solve complex security threats affecting widely used technology. Overall, Wales’s work combines large-scale platform security with cross-sector cooperation to strengthen cybersecurity for developers and the broader technology ecosystem.

gitlab

GitLab Dedicated for Government now GovRAMP-authorized (opens in new tab)

GitLab Dedicated for Government has received GovRAMP Authorization, giving state and local agencies a compliant path to adopt SaaS-based DevSecOps. Its single-tenant, U.S.-based architecture combines data residency, private networking, physical isolation, and managed infrastructure with GitLab’s development, security, and compliance capabilities. The authorization is especially timely as more states move toward mandatory GovRAMP requirements. ## Modernization Meets Security - Government agencies are increasing investments in hybrid- and multi-cloud modernization. - NASCIO’s 2025 survey ranked modernization as a top priority for state CIOs. - Agencies must modernize while addressing: - Aging IT systems and security gaps - Third-party software supply-chain risks - Ransomware and nation-state threats - Limited budgets and staffing - GitLab Dedicated for Government is designed to provide infrastructure control and compliance without requiring agencies to build and operate the underlying platform. ## GovRAMP Authorization - GovRAMP provides a standardized security and compliance assessment for state and local government cloud services. - Thirty-two states have adopted GovRAMP, with several moving toward mandatory requirements. - Authorization reduces a major procurement barrier for agencies seeking secure DevSecOps platforms. - GitLab Duo is available within the authorized environment, while GitLab Duo Agent Platform is planned for later in 2026. ## Toolchain Consolidation - Public-sector teams often use more than five development tools and more than five security tools, increasing cost, complexity, and attack surface. - Tool sprawl also creates collaboration barriers; surveyed teams reported losing roughly six hours per week to inefficient processes. - GitLab Dedicated for Government consolidates development, security, and compliance workflows on one platform. - Centralized access controls support zero-trust implementation and consistent security policies. - Open APIs and integrations allow agencies to consolidate tools gradually rather than requiring an immediate replacement of existing systems. ## Data Residency and Protection - The platform runs on GovRAMP-authorized infrastructure with data access restricted to U.S. citizens. - Private connections can link an agency’s virtual private cloud to its isolated GitLab instance without exposing services directly to the public internet. - Data is encrypted in transit and at rest. - Customers may use their own AWS Key Management Service key to control encryption for stored data. - GitLab continuously patches vulnerabilities and CVEs, reducing the infrastructure and compliance workload for agency teams. ## Managed, Single-Tenant Hosting - Each customer receives a physically isolated, single-tenant environment. - The service is U.S.-based, privately connected, and fully managed by GitLab. - Agencies can focus staff on mission priorities instead of infrastructure operations. - GitLab argues that managed hosting can provide faster time-to-value and lower total cost of ownership than self-hosting, while improving developer productivity, delivery speed, security, and compliance. ## Native Security and Compliance - Security and compliance capabilities are integrated throughout the software development lifecycle. - Built-in scanners include: - Static application security testing - Secret detection - Container scanning - Dynamic application security testing - Dependency scanning covers both direct and transitive dependencies without depth limits. - Results are available at the project and group levels, helping teams identify supply-chain risks across applications. - Findings appear directly in merge requests and pipeline security views for contextual, one-click triage. - Custom rulesets and automated security policies help reduce false positives and standardize enforcement. GitLab Dedicated for Government offers agencies a managed alternative to self-hosted DevSecOps while preserving stronger control over residency, isolation, networking, encryption, and compliance. For state and local governments preparing for stricter GovRAMP requirements, it provides a practical foundation for modernization without sacrificing security or operational control.

datadog

How we built a real-world evaluation platform for autonomous SRE agents at scale (opens in new tab)

The provided content does not include the blog post itself. It contains Datadog navigation links and a page title announcing that Datadog was named a Leader in the 2026 Gartner® Magic Quadrant™ for Observability Platforms, but no substantive discussion of the evaluation platform or its conclusions. ## Available Information - Datadog’s page promotes its recognition as a Gartner Magic Quadrant Leader. - The navigation lists products across: - Infrastructure and application monitoring - Logs, databases, and data observability - Security - Digital experience monitoring - CI/CD and software delivery - Incident and service management - AI capabilities, including Bits AI Agents and Bits Investigation - The referenced URL path suggests the intended article may concern Datadog’s “Bits AI eval platform,” but the article text is not included. ## Conclusion Please provide the full blog post content for a meaningful section-by-section summary.

aws

AWS Security Hub Extended offers full-stack enterprise security with curated partner solutions | Amazon Web Services (opens in new tab)

AWS Security Hub Extended expands Security Hub from an AWS-focused service into a broader enterprise security platform. It combines AWS services such as GuardDuty and Inspector with curated partner solutions covering endpoints, identity, email, networks, data, cloud, AI, and security operations. The plan simplifies procurement and operations through AWS billing, normalized findings, and a unified console. ## Curated Partner Security Solutions - Includes offerings from partners such as CrowdStrike, Okta, Proofpoint, SailPoint, Splunk, Zscaler, and others. - Covers security needs across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. - Lets organizations combine AWS and partner tools to detect risks spanning multiple parts of their technology stack. ## Simplified Procurement and Billing - AWS acts as the seller of record. - Customers receive pre-negotiated pay-as-you-go pricing, one monthly bill, and no long-term commitments. - Consumption-based metering is handled automatically after onboarding. - AWS Enterprise Support customers receive unified Level 1 support. ## Unified Findings and Operations - Findings from participating solutions are emitted in the Open Cybersecurity Schema Framework (OCSF). - Security Hub automatically aggregates and normalizes findings in one location. - The unified view helps teams prioritize and respond to critical risks more quickly. ## Access and Availability - Customers can find the offerings in the Security Hub console under **Management → Extended plan**. - Partner details, subscriptions, and onboarding are available directly through the console. - The plan is generally available in all commercial AWS Regions where Security Hub operates. - Pricing supports either flexible pay-as-you-go or flat-rate options. Organizations seeking broader security coverage can use Security Hub Extended to consolidate partner procurement, billing, findings, and operations through a single AWS-managed experience.

datadog

How we reduced the size of our Agent Go binaries by up to 77% | Datadog (opens in new tab)

The supplied text does not include the tech blog post itself. It contains Datadog navigation links and a promotional banner announcing its recognition as a Leader in the 2026 Gartner Magic Quadrant for Observability Platforms, but no article body or technical sections. ## Available content - Datadog promotes observability products covering: - Infrastructure and Kubernetes monitoring - Application performance monitoring - Logs and database monitoring - Security - Digital experience monitoring - Software delivery and CI visibility - Service management - AI-powered investigation and monitoring - The page links to an engineering article at: - `/blog/engineering/agent-go-binaries/` - No technical explanation, examples, conclusions, or section content from that article is included. Please provide the blog post’s full text or relevant excerpt for a substantive summary.

line

Creating the Cloud of the Future (opens in new tab)

LY Corporation is consolidating Yahoo! JAPAN and LINE’s internal cloud services into Flava, a private cloud for application development. The article outlines how Flava could evolve over the next two to three years through unified developer platforms, stronger yet more usable security, scalable multimedia storage, AI infrastructure, and intelligent cloud management. Its ultimate goal is to make complex infrastructure easier to consume while automating operational work. ## Platform Flavaization - Flava currently focuses on infrastructure, databases, and containers, while other development services are spread across separate internal platforms. - Developers must learn different systems for: - Access control and approvals - Logging, monitoring, metering, and billing - APIs, CLIs, and user interfaces - Multi-region and availability-zone operations - “Flavaization” means offering all development platforms through a consistent cloud experience. - LY expects much of this integration to be completed within the next one to two years. ## Stronger, More Usable Security - Flava incorporates security governance from the architecture and product-planning stages, working with the CISO organization. - Data environments are separated by security level: - Default - Secret - Top secret - Sensitive changes require role-based permissions, organizational reporting, expert review, and formal approval. - The main challenge is usability: - Resources can now be provisioned within minutes, but access may still require around ten workflows, such as VDI and Box account creation, taking up to two months. - VPC ACL controls can add several milliseconds of latency, which may affect latency-sensitive services such as LINE messaging. - Flava must provide “usable security” that preserves strong governance without making development excessively slow or difficult. ## Storage for Growing Multimedia Data - Users continuously generate and retain large volumes of photos, videos, and other multimedia content. - Storage demand can grow even when service traffic remains stable. - Flava needs storage technologies suited to different data lifecycles, balancing: - Cost - Throughput and latency - Searchability - Compression and deduplication - Encryption - Efficient tiered storage will be essential for managing long-lived user data economically. ## AI Operations Platforms - LY is adopting AI tools and agents across its organizations, creating demand for shared AIOps infrastructure. - Potential platform capabilities include: - Approved MCP server development and management - Vector databases - AI observability tools such as Langfuse - AI model management - Because AI systems handle internal data, these platforms must comply with company security and data-processing policies. - Flava aims to rapidly evaluate emerging AI technologies and provide compliant, standardized services across the company. ## Network and Storage Infrastructure for AI - AI workloads process larger datasets while requiring very low network latency and high throughput. - Relevant technologies include: - DPUs - Smart NICs - High-speed NVMe storage - Automated storage tiering - Operating networks and storage at cloud scale introduces major challenges in latency, reliability, fault tolerance, throughput, change management, and security. - Flava’s existing network and storage engineering teams have experience supporting LINE and Yahoo! JAPAN at large scale and will adapt that expertise for AI workloads. ## The Intelligent Cloud - Future users may describe infrastructure requirements in natural language rather than manually configuring resources through consoles, APIs, CLIs, or Terraform. - For example, Flava could translate requirements for image processing, AI-based content labeling, messaging, and tiered storage into an architecture and deployable system. - An intelligent Flava could also: - Generate network diagrams and ACL matrices - Identify vulnerabilities and prioritize remediation - Recommend cost optimizations - Detect underutilized resources - Find unencrypted personal information - Manage OSS vulnerability responses - Chatbots could automate tasks such as identifying low-utilization resources while excluding standby failover servers or proposing cost reductions for them. - Operational campaigns currently requiring substantial engineer participation could increasingly be handled by AI agents. Flava’s recommended direction is to combine a unified cloud experience with practical security, lifecycle-aware storage, AI-ready infrastructure, and natural-language automation. The article argues that building this future cloud requires both deep infrastructure expertise and strong attention to developer and user experience.

figma

Figma Achieves C5 Accreditation | Figma Blog (opens in new tab)

Figma has achieved C5 accreditation, Germany’s cloud security standard developed by the Federal Office for Information Security (BSI). The milestone strengthens Figma’s credibility with customers in Germany, Austria, and Switzerland by independently validating its security, availability, confidentiality, risk management, and operational transparency. It also supports organizations with strict regulatory and compliance requirements. ## C5 Accreditation and Cloud Security - C5 provides a recognized framework for evaluating cloud service security and reliability. - Independent accreditation confirms that Figma meets rigorous requirements for: - Information security - Risk management - Service availability - Confidentiality - Operational transparency - Figma is now listed in the BSI C5 register, allowing customers to review its security controls and operational practices more easily. ## Benefits for DACH Organizations - The accreditation gives organizations greater confidence when using Figma for cloud-based collaboration. - It is particularly relevant to customers in: - Government and the public sector - Financial services - Other highly regulated industries - Customers can more easily assess Figma against internal compliance, security, and assurance requirements. ## Continued Investment in the Region - Figma’s regional initiatives include: - Full German-language localization - European Union data storage options for enterprise customers - Expanded enterprise security and compliance capabilities - Nearly 90% of DAX 40 companies use Figma to design and build products collaboratively. Figma’s C5 accreditation reinforces its position as an enterprise-ready collaboration platform for organizations across the DACH region, especially those facing complex regulatory and security demands.

datadog

Hardening eBPF for runtime security: Lessons from Datadog Workload Protection | Datadog (opens in new tab)

The provided text does not include the blog post’s article body. It contains Datadog’s navigation menu and a link to an engineering post titled around “eBPF workload protection lessons,” so there is not enough source material to accurately summarize its technical arguments or conclusions. ## Available information - The page is hosted by Datadog’s engineering blog. - The linked topic concerns workload protection built with eBPF. - Datadog’s broader product areas include infrastructure monitoring, application performance monitoring, security, logs, and AI. - The excerpt itself does not describe: - The eBPF implementation - Design challenges or trade-offs - Performance considerations - Security detection methods - Lessons learned or recommendations Please provide the article text or a fuller extract for a substantive summary.

kakao

YEYE is Watching – (opens in new tab)

Kakao developed YEYE, a dedicated Attack Surface Management (ASM) system, to proactively identify and manage the organization's vast digital footprint, including IPs, domains, and open ports. By integrating automated scanning with a human-led Daily Security Review (DSR) process, the platform transforms raw asset data into actionable security intelligence. This holistic approach ensures that potential entry points are identified and secured before they can be exploited by external threats. ## The YEYE Asset Management Framework * Defines attack surfaces broadly to include every external-facing digital asset, such as subdomains, API endpoints, and mobile APKs. * Categorizes assets using a standardized taxonomy based on scope (In/Out/Undefined), type (Domain/IP/Service), and identification status (Known/Unknown/3rd Party). * Implements a labeling system that converts diverse data formats from multiple sources into a simplified, unified structure for better visibility. * Establishes multi-dimensional relationships between assets, CVEs, certificates, and departments, allowing teams to instantly identify which business unit is responsible for a newly discovered vulnerability. ## Daily Security Review (DSR) * Operates on the principle that "security is a process, not a product," bridging the gap between automated detection and manual remediation. * Utilizes a rotating group system where security engineers review external feeds, public vulnerability news, and YEYE alerts every morning. * Focuses on detecting "shadow IT" or assets deployed without formal security reviews to ensure all external touchpoints are accounted for. ## Scalable and Efficient Scanning Architecture * Resolved internal network bandwidth bottlenecks by adopting a hybrid infrastructure that leverages public cloud resources for high-concurrency scanning tasks. * Developed a custom distributed scanning structure using schedulers and queues to manage multiple independent workers, overcoming the limitations of single-process open-source scanners. * Optimized infrastructure costs by identifying the "sweet spot" in server specifications, favoring the horizontal expansion of medium-spec servers over expensive, high-performance hardware. * Mitigates service impact and false alarms by using fixed IPs and custom User-Agent (UA) strings, allowing service owners to distinguish YEYE’s security probes from actual malicious traffic. To effectively manage a growing attack surface, organizations should combine automated asset discovery with a structured manual review process. Prioritizing data standardization and relationship mapping between assets and vulnerabilities is essential for rapid incident response and long-term infrastructure hardening.

datadog

Detecting malicious pull requests at scale with LLMs | Datadog (opens in new tab)

Malicious pull requests can turn routine code review and CI workflows into supply-chain attack vectors. The post explains how attackers abuse automated builds—especially when workflows expose repository secrets or elevated GitHub permissions—and recommends treating all pull-request code as untrusted. Strong isolation, least privilege, careful workflow design, and monitoring are essential to prevent credential theft and unauthorized access. ## How Malicious Pull Requests Work - Attackers submit seemingly harmless changes that alter: - GitHub Actions workflows - Build or test scripts - Dependency configuration - Developer tooling - The malicious code executes automatically when CI runs the pull request. - Its goal may be to: - Exfiltrate repository or cloud credentials - Modify artifacts - Access internal systems - Establish persistence in the development pipeline ## Why CI Workflows Are Vulnerable - Pull-request jobs often execute attacker-controlled code through tests, package installation, or build commands. - Using privileged workflow events such as `pull_request_target` can expose secrets while checking out untrusted contributor code. - Broad `GITHUB_TOKEN` permissions increase the impact of a compromised job. - Secrets may leak through logs, environment variables, artifacts, or outbound network requests. ## Defensive Engineering Practices - Treat code from forks and external contributors as untrusted. - Avoid making secrets available to pull-request jobs. - Use minimal `GITHUB_TOKEN` permissions and separate privileged workflows from validation workflows. - Pin third-party GitHub Actions and dependencies to trusted commits or versions. - Require explicit approval before running workflows from untrusted contributors. - Isolate CI jobs with ephemeral runners, restricted network access, and limited filesystem permissions. - Review changes to workflow files with heightened scrutiny. ## Detection and Response - Monitor workflow behavior for unexpected network connections, credential access, or modified build outputs. - Audit repository and CI permissions regularly. - Use short-lived credentials and OIDC-based cloud access instead of long-lived static secrets. - Preserve workflow logs and artifacts to support investigation. - Revoke credentials immediately if a pull request or CI job is suspected of compromise. The practical recommendation is to design CI as though every pull request could be hostile: validate untrusted code in a restricted environment, keep secrets and write permissions out of those jobs, and require deliberate promotion into trusted workflows.

datadog

Inside Husky’s query engine: Real-time access to 100 trillion events | Datadog (opens in new tab)

The provided content does not include the blog post itself. It contains Datadog’s navigation menu and a promotional link announcing its recognition as a Leader in Gartner’s Magic Quadrant for Observability Platforms, but no substantive discussion of the linked “Husky Query Architecture” article. ## Available Content ### Datadog’s Observability Platform - Datadog promotes products covering: - Infrastructure and container monitoring - Application performance monitoring - Logs and database monitoring - Security - Digital experience monitoring - CI/CD and software delivery - Incident and service management - AI and agent observability - The navigation emphasizes Datadog’s broad, integrated platform approach. ### Gartner Recognition - The page links to Datadog’s announcement that it was named a Leader in the 2026 Gartner Magic Quadrant for Observability Platforms. - The supplied text does not include the evaluation criteria, cited strengths, limitations, or Gartner’s comparative analysis. No reliable summary of the Husky query architecture can be produced without the article’s body text.

datadog

From hand-tuned Go to self-optimizing code: Building BitsEvolve | Datadog (opens in new tab)

The provided content does not include the blog post itself. It consists primarily of Datadog’s navigation menu and a promotional link announcing its 2026 Gartner Magic Quadrant recognition. As a result, there is not enough article content to produce a reliable technical summary. ### Available Information - Datadog is promoted as a “Leader” in the Gartner Magic Quadrant for Observability Platforms. - The page links to Datadog products covering: - Infrastructure and application monitoring - Logs, databases, and data observability - Security - Digital experience monitoring - Software delivery - Incident and service management - AI and automation - The referenced blog URL appears to be titled **“Self-Optimizing System,”** but its article text is not included. Please provide the blog post’s main content or a complete page extract for an accurate summary.

datadog

Scaling down to speed up: How we improved efficiency of live process metrics by 100x | Datadog (opens in new tab)

The provided content does not include the blog post itself. It contains Datadog’s navigation menu and a promotional link announcing its recognition as a Leader in the 2026 Gartner® Magic Quadrant™ for Observability Platforms, so there is insufficient technical material to summarize the article. ### Content Included - A link to Datadog’s Gartner announcement. - Navigation categories covering: - Infrastructure and application monitoring - Logs, databases, and data observability - Security - Digital experience monitoring - Software delivery - Service management - AI capabilities - The URL suggests the intended article may concern scaling process or pipeline efficiency, but its body is not present. Please provide the full blog post text for a substantive summary.

datadog

How we built reliable log delivery to thousands of unpredictable endpoints | Datadog (opens in new tab)

Datadog’s “Reliable Log Delivery” post explains how log-collection systems can avoid losing data when networks, destinations, or agents fail. Its central recommendation is to combine acknowledgments, buffering, retries, and controlled backpressure to provide at-least-once delivery without allowing outages to overwhelm the collector. ## Why Reliable Delivery Matters - Logs are often needed during incidents, precisely when infrastructure and networks may be unstable. - Temporary destination failures can cause data loss if collectors only keep logs in memory. - Retrying without limits can create duplicate logs, unbounded memory usage, or cascading failures. ## Buffering and Persistence - Collectors should buffer logs while downstream services are unavailable. - In-memory buffers provide speed but cannot survive process crashes or host restarts. - Disk-backed queues improve durability by preserving unsent logs across transient failures. - Storage limits are necessary so a prolonged outage does not fill the host’s disk. ## Acknowledgments and Retries - A log should be removed from the queue only after the destination confirms successful receipt. - Failed or unacknowledged deliveries are retried, allowing temporary network and service failures to recover automatically. - At-least-once delivery is the practical reliability target, meaning duplicates may occur and downstream systems should handle them safely. - Retry policies should use delays and backoff rather than continuously retrying at full speed. ## Backpressure and Operational Trade-offs - When downstream systems slow down, collectors must apply backpressure instead of accepting unlimited data. - Backpressure can limit memory consumption and protect the rest of the host. - Teams must define what happens when buffers reach capacity, such as dropping the oldest data, rejecting new logs, or prioritizing important streams. - Reliability also requires monitoring queue size, delivery latency, retry rates, and dropped records. A dependable logging pipeline is not built from retries alone. It requires durable buffering, explicit delivery acknowledgments, bounded resources, and clear failure behavior; organizations should choose retention and overflow policies according to the operational value of their logs.