Aqua News

Contact Aqua PR

End-to-End Visibility: Challenges and Solutions

May 7, 2023

“Containers and cloud-native technologies allow for more efficient and scalable development, Chris Smith, Aqua CRO said, but they also increase the complexity of the environment, making it essential to have visibility and an “agent-based security approach” to identify and resolve any issues that may arise.”

Read more

Here’s What 15 Top CEOs And Cybersecurity Experts Told Us At RSAC 2023

May 1, 2023

Co-founder and CEO Dror Davidoff was featured by CRN. He shares in his insights: “For many customers, cloud security started by just getting visibility — to understand what they have in the cloud. I think there is a realization that it’s a good first step, but it’s certainly not enough.”

Read more

What To Watch For at The RSA Conference

April 24, 2023

Aqua was named a vendor to watch in Cloud Security Posture Management (CSPM).

Read more

Millions of Artifacts, Misconfigured Enterprise Software Registries Are Ripe for Pwning

April 24, 2023

Research that cloud-security vendor Aqua Security recently conducted uncovered some 250 million software artifacts and more than 65,000 container images lying exposed and Internet-accessible in thousands of registries and repositories. Some 1,400 hosts allowed access to secrets, keys, passwords, and other sensitive data that an attacker could use to mount a supply chain attack, or …

Read more

Misconfigured registries are putting hundreds of top businesses at risk

April 24, 2023

A new report from the Aqua Nautilus research team found 250 million artifacts and 65,600 container images were exposed, leaving five Fortune 500 companies, as well as “thousands of others”, at risk.

Read more

Aqua Nautilus Discovers 250 Million Artifacts Exposed via Misconfigured Registries and Artifact Repositories

April 24, 2023

BOSTON—April 24, 2023—Aqua Security, the pioneer in cloud native security, today announced that its security research team, Aqua Nautilus, discovered 250 million artifacts and 65,600 container images that were exposed via thousands of misconfigured container images, Red Hat Quay registries, JFrog Artifactory and Sonatype Nexus artifact registries. Many contained highly confidential and sensitive proprietary code …

Read more

Novel Technique Exploits Kubernetes RBAC to Create Backdoors

April 22, 2023

Researchers at cybersecurity firm Aqua Security said they recorded and analyzed an attack on its Kubernetes honeypots that used the RBAC system to gain persistence. RBAC is a method of restricting network access based on the roles of individual users within an organization.

Read more

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

April 21, 2023

“The attackers also deployed DaemonSets to take over and hijack resources of the K8s clusters they attack,” cloud security firm Aqua said in a report shared with The Hacker News. The Israeli company, which dubbed the attack RBAC Buster, said it found 60 exposed K8s clusters that have been exploited by the threat actor behind this campaign.

Read more