

Crying Out Cloud
Wiz
Welcome to "Crying Out Cloud," the monthly podcast that keeps you up to date with the latest cloud security news. Hosted by experts Eden Naftali and Amitai Cohen, each episode provides in-depth coverage of the most important vulnerabilities and incidents from the previous month. Tune in for insightful analysis and expert recommendations to help you safeguard your cloud infrastructure.
Episodes
Mentioned books

Aug 12, 2024 β’ 25min
Azure DDoS, Certificate Revocations, and ESXi Ransomware
Discover the latest in cloud security with intriguing stories about a new cryptojacking campaign targeting SeleniumGrid. Learn how a DDoS attack disrupted Starbucks due to a configuration mishap. Dive into the chaos caused by DigiCert's mass certificate revocation, and explore the dangers of trusting popular platforms with security flaws. The podcast wraps up with essential tactics to safeguard cloud environments and the ever-evolving threats presented by ransomware in the VMware ESXi world.

Aug 5, 2024 β’ 38min
Navigating Hyper Growth, AI Impact, and Mandiant Memories - Special Guest: Ryan Kazanciyan
π’ Tune in for an exclusive session with Ryan Kazanciyan on securing a security vendor, hyper-growth, and AI impact in the latest podcast episode of #CryingOutCloud!
Join our hosts, Amitai Cohen and Eden Koby Naftali, as they dive into cloud security with Ryan Kazanciyan, our seasoned expert leading security at @Wiz.
π Episode Highlights:
π Managing security during hyper growth: challenges and lessons learned.
π Ryan's experiences at Mandiant and the impact of the APT1 investigation on his approach to security.
π Current security trends and the role of AI in security.
π Ensuring safe use of AI tools like ChatGPT within the organization for internal use and product development.

Jul 17, 2024 β’ 9min
SAPwned: SAP AI Core vulnerabilities - Special Guest: Hillai Ben-Sasson
π’ Tune in to our special episode with Hillai Ben-Sasson with all you need to know about #SAPwned.
TL;DR - The Wiz Research Team uncovered serious vulnerabilities in SAP AI Core, revealing potential risks in #AI infrastructure.

Jul 15, 2024 β’ 30min
CROC Talks - Securing DBs, Cloud Threat Intel, and Detection- Special Guest: Snowflakesβ Haider Dost
π’ Tune in to Snowflake's Haider Dost for an exclusive session on Securing Databases, Cloud Threat Intelligence, and Detection strategies.
The latest podcast episode of #CryingOutCloud is LIVE! Join our special hosts, @Alon Schindel and @Eden, as they dive deep into the world of cloud security with Haider Dost, Head of Global Threat Detection and Threat Intelligence at Snowflake.
π Episode Highlights:
π Recent campaign targeting Snowflake customers.
π Discussion on the new mandatory MFA for Snowflake admins and its impact.
π Architecture of detection in the cloud & logging. What does it mean to work in a highly regulated environment compared to a fast-growing company like Snowflake.
π Defining "good security" in traditional vs. cloud-native settings.

Jun 28, 2024 β’ 24min
CROC News: Firewall Fumbles, Gitloker Etiquette, and Private Cloud Compute
π’ From data privacy norms in the age of AI
β tune in to the latest episode of #CryingOutCloud with all you need to know from the cloud security news π¨
Join Eden Naftali and Amitai Cohen as they dive into:
π How a new AI processing cloud service is challenging data privacy norms.
π‘οΈ The implications of a potential firewall misconfiguration and how to secure your environment.
π The latest ransomware attacks on GitHub repositories and how to safeguard your data.
β οΈ A new discovery by Wiz research: crypto-jacking campaign targeting Kubernetes clusters.
π Critical remote code execution vulnerability in PHP and how to mitigate the risk.

Jun 24, 2024 β’ 11min
CROC Talks: RCE Vulnerability in Ollama explained
π₯ EXCLUSIVE: Wiz Research uncovers CVE-2024-37032, aka #Probllama β a vulnerability in Ollama that that left thousands of #AI models exposed π²

Jun 6, 2024 β’ 39min
CROC Talks: Chief Llama Officer and IBM CISO - Jerry Bell
What is it like to be IBM's 'Chief Llama Officer'? π¦
ποΈ Tune in as Jerry Bell shares his journey from crashing his first computer at 10 to leading IBM's Public Cloud Security
What's on today's agenda?
π² Managing a popular 'Mastodon' server post-Twitter acquisition
π‘οΈ Challenges and surprises as IBM's CISO
π Insights on the security implications of M&A

May 27, 2024 β’ 23min
CROC News: Ninjas, Grand Theft AI, and Backlogged CVEs
ποΈ All that's π₯ in the cloud: From logging and cloud attacks to NVD backlog updates.
what's on today's agenda?
1οΈβ£ Discover how logging bypass made password-spray attacks undetectable.
2οΈβ£ Learn about the latest way attackers are monetizing cloud access - by selling access to other people's AI models.
3οΈβ£ NVD's ongoing backlog - Hear about how the industry is dealing with it.

May 9, 2024 β’ 34min
CROC Talks - Threat Models, Cloud Tools, and Security Tales - Special Guest: Kat Traxler
Our latest episode of Crying out cloud features none other than Kat Traxler, a seasoned security professional renowned for her expertise in cloud research.π
Here's a sneak peek at what we'll cover:
π Threat modeling: Kat's practical insights
π§ "DeRF": Kat's revolutionary tool and how it can help cloud security practitioners
π‘ Dispelling myths about cloud security and how it challenges the OSI model
π¬ Future research directions in cloud security & Kat's latest projects in the field

Apr 4, 2024 β’ 11min
CROC Talks: Helping Secure Hugging Face Hub - Special Guest: Shir Tamari
π¨ BREAKING: Wiz Research identifies critical risks in #AI-as-a-service π¨
Dive into Crying Out Cloud's latest episode, featuring a very special guest, Shir Tamari, head of the research team at Wiz. This episode sheds light on the security challenges that come with the rapid integration of AI technologies. Highlights include:
π Exploring the rapid integration of AI and its associated security risks, identified by Wiz Research in collaboration with Hugging Face.
π‘οΈ Exposing two significant security flaws within Hugging Face's systems: shared inference and CI/CD systems, which could potentially offer unauthorized access to sensitive data.
π’ Highlighting the critical need for robust security frameworks in AI services.
β
Demonstrating Hugging Face's dedication to security through the adoption of Wiz CSPM, continuous vulnerability assessments, and annual penetration tests, thereby establishing a high standard in AI safety.


