Mondoo
All Posts

Cloud Security

Security for AWS, Azure, GCP, and SaaS applications

12 articles

Augment Microsoft Defender for Cloud with Mondoo Exposure Management
4 min read

Augment Microsoft Defender for Cloud with Mondoo Exposure Management

What do you get when you combine Microsoft Defender for Cloud (MDC) with the contextual risk prioritization and vulnerability and misconfiguration detection of Mondoo’s exposure management platform? The answer: A complete, centralized, and actionable list of all the misconfigurations and vulnerabilities in your environment—prioritized by the actual risk they pose to your organization.

Deborah Galea
Deborah Galea · Dec 19, 2024
Continuous Domain Health Checking and Compliance
2 min read

Continuous Domain Health Checking and Compliance

Over the last decade, we’ve seen an explosion in the complexity of attacks on business infrastructure. New zero-day attacks and ransomware breaches have become weekly news topics. Businesses have reacted with new security practices and tooling meant to thwart attackers, but in the pursuit of cutting-edge defenses, have we missed the most basic part of securing business infrastructure? Attackers don’t need complex, zero-day exploits to compromise your business if your web properties and domains are not properly secured.

Tim Smith
Tim Smith · Feb 12, 2024
GCP Security from CSPM to Agentless VM Scanning
6 min read

GCP Security from CSPM to Agentless VM Scanning

The shift from traditional data centers to the cloud has changed how we provision systems. Gone are the days of waiting for vendors, painstakingly slow rack and stack processes, and manual OS installations. Today, you can launch new systems into production within minutes using a few clicks or API calls. While this has increased convenience and agility, it has also introduced significant challenges for security teams that even modern Cloud Security Posture Management (CSPM) solutions often miss.

Tim Smith
Tim Smith · Sep 20, 2023
Whats new in CIS Amazon Web Services Foundations 2.0
2 min read

Whats new in CIS Amazon Web Services Foundations 2.0

The Center for Internet Security (CIS) recently released an updated 2.0 version of their Amazon Web Services (AWS) Foundations benchmark. This updated release ships with several significant changes, including new security recommendations and the removal of outdated practices.

Tim Smith
Tim Smith · Sep 11, 2023
Mondoo supports Oracle Cloud Infrastructure for enhanced IT security
2 min read

Mondoo supports Oracle Cloud Infrastructure for enhanced IT security

We're excited to announce that Mondoo now extends its robust security and compliance solution to Oracle Cloud Infrastructure (OCI). This integration quickly and easily connects Mondoo’s comprehensive security solution to OCI in minutes. OCI customers can use Mondoo’s tools to find, prioritize, and fix security risks in their cloud workloads.

Chip Johnson
Chip Johnson · Aug 30, 2023
Effortless and Continuous Azure VM Instance Scanning
2 min read

Effortless and Continuous Azure VM Instance Scanning

The shift from traditional data centers to the cloud has changed how we provision systems. Gone are the days of waiting for vendors, painstakingly slow rack and stack processes, and manual OS installations. Today, new systems can be launched into production within minutes using a few clicks or API calls. While this has increased convenience and agility, it has also introduced significant challenges for security teams.

Tim Smith
Tim Smith · Aug 8, 2023
Secure Your SaaS Applications with Mondoo's Open SSPM Solution
5 min read

Secure Your SaaS Applications with Mondoo's Open SSPM Solution

The modern business landscape is evolving rapidly, with more and more organizations shifting their processes, user data, corporate data, and customer relationship management (CRM) solutions to SaaS applications.

Christoph Hartmann
Christoph Hartmann · Mar 22, 2023
SSL/TLS Certificate Verification: How to Identify Expired Certificates
2 min read

SSL/TLS Certificate Verification: How to Identify Expired Certificates

Verifying SSL/TLS certificates and establishing effective certificate management in your environment can be challenging. With cnquery's cloud-native asset inventory capabilities, you can retrieve all information about your deployed certificates and their certificate chain across your entire infrastructure. With cnspec's cloud-native solution to assess the security and compliance, you can enforce that your certificates and their certificate chain are verified as well as not expired all the time.

Patrick Münch
Patrick Münch · Jan 12, 2023
Finding Lost AWS Resources with cnquery
1 min read

Finding Lost AWS Resources with cnquery

We all understand that resources get lost in the cloud. Between working across regions, migrating accounts, and the ability to quickly spin up an instance and forget about it, it’s almost inevitable to have some mystery resources lurking in your AWS account.

Victoria Jeffrey
Victoria Jeffrey · Dec 5, 2022
Side Scanning EC2 Instances with cnspec
1 min read

Side Scanning EC2 Instances with cnspec

Just when you think you can’t have it all, you can.

Victoria Jeffrey
Victoria Jeffrey · Dec 2, 2022
Reveal Vulnerabilities in AWS EC2 Instances with cnspec
1 min read

Reveal Vulnerabilities in AWS EC2 Instances with cnspec

Vulnerabilities are bad. We all know this. They expose your infrastructure to attackers.

Victoria Jeffrey
Victoria Jeffrey · Nov 25, 2022
9 AWS Security Mistakes for DevOps Teams
11 min read

9 AWS Security Mistakes for DevOps Teams

AWS introduces new complexity to your infrastructure. With that complexity comes potential security risk to the organization. Amazon’s shared responsibility model places the reality of security within the cloud squarely in the hands of the DevOps team

Letha DunnBen Rockwood
Letha Dunn, Ben Rockwood · May 26, 2022

Ready to Transform Your Security?

See how Mondoo can help you find and fix vulnerabilities faster.