Intelligence

AppSec & Compliance

Technical analysis of cloud vulnerabilities, NIS2 and SOC2 controls, GCP misconfigurations, and breach post-mortems — updated daily.

47 posts

Breach Analysis ·

Hardening GCP Identity MFA Against Social Engineering: Lessons from the Uber 2022 Breach

The Uber 2022 social engineering breach highlights the critical need for phishing-resistant MFA and robust identity governance for GCP workloads.

Read more →
Breach Analysis ·

LastPass Vault Breach Secret Management GCP Lessons for Resilient Architectures

The LastPass breach offers critical insights into securing secrets on GCP, emphasizing distributed management and contextual access controls.

Read more →
Breach Analysis ·

SolarWinds Supply Chain Compromise: CI/CD GCP Lessons for Robust Security

The SolarWinds compromise highlighted critical CI/CD vulnerabilities. Learn how to apply these lessons to secure your GCP build and deployment pipelines.

Read more →
GCP Security ·

Workload Identity Federation Attack Surface Hardening on GCP

Hardening Workload Identity Federation on GCP requires precise trust policy configuration and continuous validation against real-world attack vectors.

Read more →
GCP Security ·

Securing Cloud Build Supply Chains with SLSA Level 3 Attestations

Strengthen your software supply chain by implementing SLSA Level 3 attestations in Cloud Build, ensuring verifiable provenance and integrity for all deployed artifacts on GCP.

Read more →
GCP Security ·

Enforcing Robust Secret Manager Rotation Policies and Access Audit

Securely managing secrets on GCP requires stringent rotation policies and comprehensive access auditing to mitigate compromise risks.

Read more →
GCP Security ·

Securing Data at Rest: Cloud KMS Key Rotation Automation with Cloud Scheduler

Automate Cloud KMS key rotation using Cloud Scheduler and Cloud Functions to enhance data security and maintain compliance with minimal operational overhead.

Read more →
GCP Security ·

BigQuery Data Exfiltration Prevention with Column-Level Security

Secure sensitive BigQuery data against exfiltration using column-level security and Data Catalog policy tags for granular access control.

Read more →
GCP Security ·

Achieving Robust Cloud SQL IAM Authentication Hardening Audit

Strengthen Cloud SQL security by implementing and auditing IAM database authentication, mitigating credential risks and improving compliance posture.

Read more →
Compliance ·

Achieving GDPR Data Residency Enforcement in GCP Multi-Region Deployments

Enforce GDPR data residency across GCP multi-region deployments by architecting data locality, access controls, and audit trails to meet strict compliance requirements.

Read more →
Compliance ·

Streamlining NIST CSF 2.0 GCP Security Controls Mapping

Understand how runred.ai automates NIST CSF 2.0 compliance by mapping native GCP security controls to the framework's core functions, ensuring continuous evidence generation.

Read more →
Compliance ·

Streamlining FedRAMP Moderate Baseline GCP Controls Mapping

Automate continuous compliance for FedRAMP Moderate on GCP by linking source code to infrastructure context and generating immutable audit evidence.

Read more →
Compliance ·

Enforcing ISO 27001 A.8.28 Secure Coding Standards in the Cloud

Implement ISO 27001 A.8.28 secure coding standards in your GCP environment to mitigate critical vulnerabilities and streamline audit evidence generation.

Read more →
Compliance ·

Contextual SOC2 CC7.2 Anomaly Detection on GCP

Implement robust SOC2 CC7.2 anomaly detection on GCP by correlating application behavior with live infrastructure context to identify deviations.

Read more →
Compliance ·

Meeting PCI DSS 4.0 GCP Payment Processing Requirements

Understand the critical PCI DSS 4.0 GCP payment processing requirements to secure cardholder data environments and maintain compliance on Google Cloud Platform.

Read more →
Compliance ·

Implementing HIPAA Technical Safeguards for GCP Healthcare Workloads

Understand the critical technical safeguards required by HIPAA for protected health information (PHI) on Google Cloud, ensuring compliance and data integrity.

Read more →
Compliance ·

Achieving EU AI Act High-Risk System Compliance on GCP

The EU AI Act mandates stringent controls for high-risk systems. Engineering teams on GCP must establish verifiable compliance frameworks to mitigate operational and legal exposure.

Read more →
AppSec ·

Exploit-First Testing for Automated AppSec Patch Verification

Implement exploit-first testing to verify security patches automatically, ensuring vulnerabilities are closed before deployment and strengthening your automated AppSec posture on GCP.

Read more →
GCP Security ·

Hardening GCP Cloud Armor WAF with OWASP Top 10 Configuration Rules

Implement robust GCP Cloud Armor WAF OWASP Top 10 configuration rules to protect your applications from common web vulnerabilities.

Read more →
AppSec ·

Optimizing Developer Velocity Security Balance with Automated AppSec

Eliminate the false tradeoff between speed and security by integrating automated AppSec directly into your GCP development lifecycle.

Read more →
Compliance ·

Meeting DORA Compliance Technical Requirements for Financial Cloud on GCP

DORA mandates stringent ICT risk management for financial entities on GCP. Understanding technical requirements is critical for operational resilience.

Read more →
Breach Analysis ·

Twitch 2021: Source Code Exposure, Access Control, and Cloud Post-Mortem Lessons

The Twitch 2021 breach exposed critical source code and highlighted severe access control failures, offering vital lessons for GCP engineering teams on preventing similar cloud incidents.

Read more →
Compliance ·

A CIS Controls v8 Google Cloud Implementation Checklist for Production Workloads

This CIS Controls v8 Google Cloud implementation checklist provides actionable steps for securing production environments and ensuring compliance on GCP.

Read more →
AppSec ·

Reduce MTTR for Cloud Vulnerabilities: Automated Remediation Strategies

Expedite vulnerability patching on GCP by implementing automated remediation workflows, significantly reducing mean time to remediate and improving overall security posture.

Read more →
Breach Analysis ·

Securing Third-Party Access for Production Cloud Breach Prevention

Robust controls for third-party access are critical to prevent breaches in production cloud environments, demanding least privilege and continuous monitoring.

Read more →
GCP Security ·

Mitigating Cloud Functions Injection Vulnerabilities for Robust Serverless GCP Security

Understand how Cloud Functions injection vulnerabilities expose serverless GCP applications and learn practical strategies to harden your deployments against common attack vectors.

Read more →
OWASP ·

Mitigating OWASP A05 Security Misconfiguration in GKE Kubernetes Deployments

Address critical OWASP A05 security misconfigurations in GKE to prevent unauthorized access and maintain robust cloud-native security postures.

Read more →
Compliance ·

NIS2 Incident Reporting Requirements: Cloud SaaS Obligations on GCP

Understand how NIS2 incident reporting requirements impact your cloud SaaS obligations on GCP, focusing on detection, classification, and timely communication protocols.

Read more →
AppSec ·

SAST DAST Context-Aware Scanning Comparison on GCP

Understand the differences between SAST, DAST, and context-aware scanning to secure your GCP applications effectively and efficiently.

Read more →
Breach Analysis ·

Preventing an MFA Fatigue Attack Cloud Network Segmentation Breach on GCP

The Uber 2022 breach highlighted critical lessons in identity protection and network segmentation for cloud environments, directly applicable to GCP.

Read more →
GCP Security ·

Strengthening GCP VPC Service Controls Security Bypass Prevention

Proactive measures are essential to prevent data exfiltration and maintain perimeter integrity within your GCP VPC Service Controls.

Read more →
AppSec ·

Automated Penetration Testing ROI vs Manual Enterprise: A GCP View

Evaluate the financial and security benefits of automated penetration testing over traditional manual methods for enterprise workloads on Google Cloud.

Read more →
Compliance ·

Streamlining SOC2 Type II Continuous Monitoring GCP Implementation

Automate SOC2 Type II continuous monitoring on GCP by connecting source code to infrastructure context, ensuring audit readiness and real-time compliance verification.

Read more →
OWASP ·

SSRF Attack GCP Metadata Service Prevention: Securing Your Workloads

Mitigate Server-Side Request Forgery (SSRF) risks targeting the GCP metadata service, preventing credential exfiltration and unauthorized resource access within your Google Cloud environment.

Read more →
Breach Analysis ·

Enhancing Developer Environment Security Breach GCP Prevention

The LastPass breach offers critical lessons for securing developer environments and preventing data exfiltration in GCP.

Read more →
Compliance ·

Streamlining ISO 27001 A.12.6 Vulnerability Management Automation in the Cloud

Automate ISO 27001 A.12.6 vulnerability management on GCP, connecting code to infrastructure for contextual risk scoring and verifiable audit evidence.

Read more →
OWASP ·

Mitigating OWASP A01 Broken Access Control in Cloud Run Microservices

Understand and prevent critical OWASP A01 broken access control vulnerabilities in your Cloud Run microservices with actionable strategies.

Read more →
GCP Security ·

Achieving GCP IAM Least Privilege Automated Enforcement

Automate GCP IAM least privilege enforcement to reduce attack surface and ensure compliance, connecting source code context with live infrastructure.

Read more →
Compliance ·

Meeting the NIS2 Compliance Deadline: Cloud Companies Requirements for GCP Infrastructure

The NIS2 Directive mandates robust cybersecurity for critical entities. Cloud-native companies on GCP must implement specific controls to meet the upcoming compliance deadline.

Read more →
Breach Analysis ·

Capital One Lessons: Cloud Storage Misconfiguration Breach GCP Prevention

The Capital One breach highlighted critical cloud storage misconfiguration risks. Learn how to implement robust prevention strategies on GCP.

Read more →
AppSec ·

Implementing Shift-Left Security in Your CI/CD GCP Pipeline

Integrate security early in your GCP CI/CD pipelines to reduce risk and ensure compliance with automated vulnerability discovery and validation.

Read more →
OWASP ·

Navigating OWASP Top 10 2025 Cloud API Security Changes

The upcoming OWASP Top 10 2025 will refine focus on critical cloud API risks, demanding proactive security posture adjustments for GCP-native applications.

Read more →
Breach Analysis ·

MOVEit SQL Injection Prevention: Parameterised Queries on GCP

Understand how parameterised queries prevent SQL injection vulnerabilities like those exploited in MOVEit, securing your GCP applications against data exfiltration.

Read more →
GCP Security ·

Preventing GKE RBAC Privilege Escalation Paths

Understand and mitigate critical GKE RBAC privilege escalation vulnerabilities to secure your Google Kubernetes Engine clusters.

Read more →
GCP Security ·

Mitigating Cloud Run SQL Injection Exposure in Production

Understand how Cloud Run SQL injection exposure impacts your GCP environment and implement robust defenses to protect sensitive data.

Read more →
Compliance ·

Streamlining SOC2 CC6.8 Automated Evidence on GCP

Automate SOC2 CC6.8 change management evidence collection on GCP by linking source code changes to immutable Cloud Logging records, ensuring audit readiness.

Read more →
Compliance ·

Implementing a NIS2 Article 21 Technical Controls Checklist on GCP

Engineering teams on GCP need a clear NIS2 Article 21 technical controls checklist to manage risk and demonstrate compliance effectively.

Read more →