Upwind Cloud Security Platform bridges intelligence from runtime to build-time, eliminating friction & boosting the productivity of your developers, security engineers, and DevOps.
Upwind delivers comprehensive cloud security, precisely when and where it’s most critical.
Upwind is the runtime-powered cloud security platform that leverages runtime data to secure your cloud infrastructure. Upwind helps you mitigate the risks that actually matter, identify the root causes of threats in minutes and respond with context and automation.
Upwind protects everything you run in the cloud in one centralized platform, whose capabilities include CSPM, DSPM, CWPP, CDR, API security, vulnerability management, identity security and container security.
Quick trip down to San Diego to spend time with some of my favorite people — Eric Goldstein, Jake Martens, Farzan Sharifzada, Moudy Elbayadi, Ph.D., Sara Sullivan — and celebrate EVOTEK’s partnership with Upwind Security.
We had the chance to unveil their signage at Petco Park, home of the San Diego Padres — such a great moment to recognize the momentum we’re building together.
What made the day even more meaningful is that it came just hours after Upwind identified an active zero-day supply chain attack in npm. They’re already working closely with customers to investigate, contain, and understand the full scope. They’re calling it “Nodes to Snakes” — and it’s a strong reminder of how critical speed, expertise, and partnership are in moments like this.
Looking forward to what we build together next. Let’s go!
Cesar EncisoNed EngelkeMatt ShufeldtBrad Clayton
It’s AWS Summit season! We’re excited to be across Bengaluru, Singapore, and Sydney.
Come meet the Upwind team and discover how we’re redefining modern cloud security with a true runtime-first approach, and why we’ve been selected as an AWS CNAPP Partner of Choice in AWS Security Hub.
Join us for live demos, great conversations, and a few surprises along the way.
Looking to connect 1:1? Book time with us onsite 👉 https://lnkd.in/gMZaVDmD
See you there 🏄♂️ Up & Up
#AWSSummit#CloudSecurity#AWS#CNAPP#AWSSecurityHub Gavin MarcAnthonySimarpreetNelsonLaviMeganRyanHimanshuCheyenneArielPrabhjot
🚨 Active Zero-Day Alert: The threat research team at Upwind Security has identified and is actively responding to a new, highly evasive supply chain attack in npm dubbed "Nodes to Snakes."
This isn't a spray-and-pray campaign. Malicious packages are deploying scripts that fingerprint the host environment before pulling a second-stage payload, completely evading traditional static and sandbox detection.
These threats aren't hacked into your system; they are invited in through trusted dependencies. If you rely on external npm packages, it is urgent that you verify what is actually executing in your environment at runtime, not just what was installed.
🔗 Read Upwind’s full technical breakdown and ongoing updates here: https://lnkd.in/gDa9Xgxh
We're welcoming Drata to the Upwind Lineup, our tech alliance program, and this one solves a problem we hear about constantly.
Cloud security has improved visibility. But proving it is still a challenge.
Security teams can see risk in real time. But when audits, reviews, or enterprise deals come around, they're still pulling screenshots, chasing down evidence, and stitching together point-in-time snapshots of a constantly changing environment.
The security reality and the compliance record live in two different worlds. That gap is exactly where this partnership begins.
Upwind provides the runtime context, what's actually happening in your environment right now: which vulnerabilities are truly exploitable, which identities are actively in use, which workloads and APIs are behaving abnormally. It's live signal, not stale data.
Drata takes that signal and maps it to controls, creating continuous, audit-ready evidence without manual exports.
The result is a clean flow: runtime signal → mapped control → continuous proof.
Instead of last-minute audit scrambles and fragmented documentation, teams get a compliance posture that reflects their actual security posture, at all times.
Because in modern cloud environments, trust isn't a report you generate once a quarter. It's something you should be able to prove at any moment.
Excited to build this out with the Drata team. 🤝
Up & Up! 🏄♂️
We’re in the middle of another wave of supply chain attacks, and this one is already active 🚨
We’ve identified an active zero-day supply chain attack in npm, and we’re working with customers right now to investigate, contain, and understand the scope.
Here’s what we know so far, on what we're calling Nodes to Snakes:
• A malicious package pulls a Python script (ld.py) from a remote source
• The script fingerprints the host and builds a unique identifier
• Only then does it retrieve the second stage, likely to evade static and sandbox-based detection
• Data is exfiltrated over port 8000 after being encoded and tied to that unique host signature
• The attacker bypasses standard OS commands, directly accessing low-level system artifacts
• Includes continuous monitoring of the process tree and attempts to extract sensitive data
This is not a spray-and-pray attack. It’s selective. It profiles the environment first, then decides how to proceed, a clear attempt to stay ahead of traditional detection approaches.
We identified this early and are actively supporting impacted customers while continuing to analyze new samples in real time.
What we’re focused on now:
• Understanding second-stage delivery conditions
• Tracking how stolen data and credentials are being used
• Identifying indicators that can help teams detect this before damage is done
Supply chain attacks like this don’t break in, they’re invited in through trusted dependencies. And once inside, they operate at runtime, where visibility is often limited.
Our threat research team is on standby and will continue sharing validated findings as they come in. If your team needs support, please reach out we are here to help.
If you're running workloads that rely on external npm packages, it's urgent that you go and verify what’s actually executing in your environment, not just what was installed.
More updates coming soon. For updates and current details, see our blog via link in comments.
Congratulations Inaugural Resilient #CISO Award Honorees and Trailblazer Award Winners
Absolute Security is excited to announce the first honorees for the inaugural Resilient CISO Award and winners of the Trailblazer Awards. The Resilient CISO Award was sponsored in partnership with CyberRisk Alliance and SC Media. The Trailblazer Awards are a category created by a special panel of industry security and risk leaders. Honorees, winners, and finalists were announced at special events during RSAC Conference 2026 and featured on the Nasdaq Tower in Times Square, NY, NY.
The 2026 Inaugural Resilient CISO Award Honorees: Vince Aimutis, VP, Director of Information Services and CISO, Federated Mutual Insurance Company; Andres Andreu, CISO, Constella Intelligence; Sharon Kelley, Executive Director for Information Security and Chief Information Security Officer, New Jersey Institute of Technology; Allen O. Ohanian, CISO, LA County DCFS; Rinki Sethi, CISO and CSO, Upwind Security.
The 2026 Inaugural Trailblazer Award Winners: Andrew Albrecht, MBA, VP, Chief Information Security Officer, Domino's; Morgan Bjerke, Chief Information Security Officer, Thomson Reuters; Deneen DeFiore, Vice President & Chief Information Security Officer, United Airlines; Sebastian Goodwin, SVP, Chief Trust Officer, Autodesk; Abhishek Jha, Global Chief Information Security Officer, Tata Technologies; Barbara O'Neill, Global Chief Information Security Officer, Ernst & Young; Margarita Rivera, Global Chief Information Security Officer, Carnival Corporation; Bradley Schaufenbuel, Vice President and Chief Information Security Officer at Paychex.
The 2026 Inaugural Resilient CISO Award Finalists: Krista Arndt, Associate CISO, Semperis; Srinivasan Balraj, VP, Information Security and Compliance (CISO), Muthoot Fincorp LTD; Gary Brickhouse, CISO, GuidePoint Security; David B. Cross, Chief Information Security Officer, Atlassian; Auston Davis, CISM, CISO, City of San Jose; Dr. Darren Death, Chief Information Security Officer, Chief Privacy Officer, and Deputy Chief AI Officer, Export–Import Bank of the United States (EXIM); Dara Gibson, CEO and vCISO, Cybersecurity Readiness Advisors LLC; Abhishek Jha, CISO, Tata Technologies; Marcel Lehner, CSO, Wiener Stadtwerke GmbH; Nidhi Luthra, CISO, Baxter Healthcare; Saikat Maiti, CISO, nfactor; Diego Neuber, CISO, Disatech IT Solutions; Hugh Percy, Chief Information Security Officer (CISO), Northside Hospital; V V Subba Raju CISM, CISA, CRISC, CISO, iBasis; Glen Vickers, Head of IT and CISO, ABS Wavesight.
Why Salesforce Ventures sees runtime as foundational to the future of cloud security ☁️
Security and DevOps teams are looking for more than visibility. They want guidance they can act on so they can move fast, and Salesforce Ventures believes Upwind’s focus on runtime makes that possible with meaningful ROI.
Runtime is not just for detection and response. It can fundamentally improve the entire security stack. When runtime is brought into CSPM, vulnerability management, and data security, teams get better context and a more actionable way to secure cloud environments.
The same shift is already shaping what comes next, from AI security to application security.
Watch the full interview via link in comments below.
Up & Upwind! 🌊
Amiram Shachar
What a special week in SF at the High Tide House 🌁🌊
This week, we brought the Upwind High Tide House to San Francisco for the biggest week in cybersecurity and created something we're really proud of: a calm in the middle of the storm for security teams and leaders to connect, recharge, and just be in community.
All week, the house was full of builders, security leaders, and friends of the community.
From early coffee chats to late-night conversations, from new connections to familiar faces, this is exactly what we hoped it would be.
We’ll share more from each moment throughout the week.
To everyone who stopped by for a coffee, grabbed something from the surf shop, caught a ride on our pedicab, laced up for Cyberkicks, or just sat down for a real conversation, thank you. This is exactly why we created this experience. 💙
Up & Up. 🤙