Sign in to view Amiram’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Amiram’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
United States
Sign in to view Amiram’s full profile
Amiram can introduce you to 10+ people at Upwind Security
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
21K followers
500+ connections
Sign in to view Amiram’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Amiram
Amiram can introduce you to 10+ people at Upwind Security
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Amiram
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Amiram’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Articles by Amiram
-
A Spoiler from Spotinst's Advisor
A Spoiler from Spotinst's Advisor
Run your Hadoop on Spot, Scale up your instances with Spot, Provision Smarter with Spotinst. https://www.
28
Activity
21K followers
-
Amiram Shachar shared this🚨Amiram Shachar shared thisWe’re in the middle of another wave of supply chain attacks, and this one is already active 🚨 We’ve identified an active zero-day supply chain attack in npm, and we’re working with customers right now to investigate, contain, and understand the scope. Here’s what we know so far, on what we're calling Nodes to Snakes: • A malicious package pulls a Python script (ld.py) from a remote source • The script fingerprints the host and builds a unique identifier • Only then does it retrieve the second stage, likely to evade static and sandbox-based detection • Data is exfiltrated over port 8000 after being encoded and tied to that unique host signature • The attacker bypasses standard OS commands, directly accessing low-level system artifacts • Includes continuous monitoring of the process tree and attempts to extract sensitive data This is not a spray-and-pray attack. It’s selective. It profiles the environment first, then decides how to proceed, a clear attempt to stay ahead of traditional detection approaches. We identified this early and are actively supporting impacted customers while continuing to analyze new samples in real time. What we’re focused on now: • Understanding second-stage delivery conditions • Tracking how stolen data and credentials are being used • Identifying indicators that can help teams detect this before damage is done Supply chain attacks like this don’t break in, they’re invited in through trusted dependencies. And once inside, they operate at runtime, where visibility is often limited. Our threat research team is on standby and will continue sharing validated findings as they come in. If your team needs support, please reach out we are here to help. If you're running workloads that rely on external npm packages, it's urgent that you go and verify what’s actually executing in your environment, not just what was installed. More updates coming soon. For updates and current details, see our blog via link in comments.
-
Amiram Shachar shared thisBig supply chain attack is active now in the wild. DM us if you need help with identifying / scanning.Amiram Shachar shared thisThe best way to abuse the RSA jet lag is to discover a supply chain attack in production affecting multiple customers. Details will be shared soon 🏄♂️ Dan Yahav Omer Idel what an outstanding work! Please note that the timestamps in the screenshots are shown in GMT+3, which is equivalent to late 30.03 ET
-
Amiram Shachar shared thisBuilding. 💯⚡️Amiram Shachar shared thisAsked Claude to evaluate the Cloud Security market for a fund thesis. It came back with this. In under 90 seconds. 15 companies ranked by momentum score. Funding history, employee growth, estimated valuations for the top 5. Overvalued companies flagged. Companies likely coming back to market identified. One prompt. One answer. Real data. This is the CybersecTools MCP Server. It connects Claude, Cursor, or any AI agent directly to our database of 10,000+ cybersecurity products and 2,800+ companies. No copy-pasting. No tab-switching. No stale spreadsheets. Here's what it pulled in that single query: 🔹 Upwind scored 72 (Accelerating). 138% headcount growth. Bessemer leading the Series B. Valuation looks justified at 17.5x on $80M revenue. 🔹 Cloudflare's $75.8B market cap vs $17.5B estimated fair value. 37.6x P/S is pricing in AI/edge compute narrative, not cloud security economics. 🔹 CoreStack flagged: 54.8x revenue multiple on $11.3M revenue. Headcount shrinking 19% YoY. Last equity round was Nov 2021. Took $50M debt in 2025. Down round or strategic exit incoming. 🔹 Sysdig, Obsidian Security, AppOmni all flagged with 18+ month funding gaps. The momentum scoring methodology weighs three pillars: growth signals, market presence, and funding velocity. It's not a vanity metric. It's built on the same data layer that tracks every product, feature, and integration across the cybersecurity landscape. This depth of analysis is available on the Professional plan. If you're an investor running due diligence, a vendor tracking competitors, or an analyst covering cybersecurity, the MCP Server turns your AI workspace into a market intelligence terminal.
-
Amiram Shachar shared thisTo all the builders out there. ⚒️Amiram Shachar shared this“When you run a company, 80% of your day is bad.” Our own Nowi Kallen sat down with Amiram Shachar ahead of Upwind Security’s $250M Series B announcement and he shared some sage advice that he received early on. As a founder, you spend most of your time dealing with things that are broken, late, or harder than you expected. You solve one problem and two more appear. But, as Amiram puts it, that’s not a bad thing. Once you accept that this is the job, you stop treating friction like a sign that something has gone wrong. In most cases, it’s a sign that you’re in the work. You just have to learn to stay locked in, keep solving, and not let every setback shake your belief. 🎥 Watch Nowi's full conversation with Amiram in the comments below.
-
Amiram Shachar shared thisIt was a privilege sharing the stage at Cybersparx with Guru Chahal , Yevgeny Dibrov and Isaac Evans and talk about the important partnership between Upwind Security and AWS as Upwind becomes the CNAPP of choice inside the AWS Security Hub and what it means for the future of Cloud Security. Up & Up!
-
Amiram Shachar shared thisWelcome to the Upwind Security family, Salesforce Ventures! ♥️ Nowi Kallen , Kartik Gupta - excited to build with you. Up & Up!Amiram Shachar shared thisAnnouncing our investment in Upwind Security's $250M Series B 🤝 Upwind is built for the reality of modern cloud environments, where static scans and daily snapshots no longer cut it. Using eBPF, its runtime-first approach gives teams deep visibility into live workloads without the burden of legacy agents. That inside-out architecture lets Upwind do what static scanners can’t: determine reachability. By pairing build-time data with real-time runtime context, Upwind can show which vulnerabilities are genuinely exploitable in production. If a vulnerable library is sitting on disk but never loaded into memory, it’s not treated as an urgent risk. The result is roughly 95% less alert noise, so security teams can focus their time on what matters. We’ve known Amiram Shachar, Tal Zur, and Lavi Ferdman since their Spot.io days, and stayed close because it was obvious they had something special: serious technical depth, strong founder chemistry, and a clear view of where the market was heading. That direction feels even more important now. AI is reshaping the cloud and expanding the attack surface along with it. New risks are emerging fast, from model theft to data poisoning to entirely new security requirements around AI workloads. At the same time, those workloads are dynamic, complex, and resource-intensive, which makes traditional approaches feel increasingly outdated. We believe this change will continue to drive value into CNAPP, one of the most important and fastest-growing categories in cloud security. The Upwind team is building with real urgency, real conviction, and real product insight. We’re thrilled to partner with them as they continue to raise the bar for what modern cloud security should look like. 🔗 In a new blog post, Nowi Kallen and Kartik Gupta shared more about our investment in Upwind: https://lnkd.in/ez2-BP5i
-
Amiram Shachar shared thisGearing up for RSA next week. Come say hi at the Upwind High Tide House @ The Box San Francisco. Incredible lineup of sessions, speakers and roadmap sessions.
-
Amiram Shachar shared thisCybersparx… The concentration of talent per square foot at this conference is simply among the most impressive I’ve ever witnessed in my life.
-
Amiram Shachar shared thisComing soon. Your Cloud Security + APIs @ Runtime like you've never seen before. 🌊
-
Amiram Shachar liked thisBig supply chain attack is active now in the wild. DM us if you need help with identifying / scanning.Amiram Shachar liked thisThe best way to abuse the RSA jet lag is to discover a supply chain attack in production affecting multiple customers. Details will be shared soon 🏄♂️ Dan Yahav Omer Idel what an outstanding work! Please note that the timestamps in the screenshots are shown in GMT+3, which is equivalent to late 30.03 ET
-
Amiram Shachar liked thisAmiram Shachar liked this🚨🏄🏻♂️We detected ANOTHER live npm supply chain attack in production, before any CVE, a scary name, or signature existed. We mainly saw a live malicious process flow of; node → sh → curl → python3 What this means (in simple terms): • A normal Node.js app suddenly opened a shell • The shell downloaded a file from the internet • Then executed it using Python 👉 In short: legitimate app → downloads payload → runs it → Game over. (see process tree, screenshot #1 👇) _________ Why it triggered and how Upwind works (behavior vs baseline) This workload never: • spawned Python (process monitoring) • wrote to /tmp (file integrity baselining) • called unknown external domains (network profiling) • triggered unusual API flows (API behavior monitoring) • executed chained shell commands from Node (process lineage anomaly) 👉 Behavior broke the baseline What it maps to (now public) • axios@1.14.1, 0.30.4 compromised • RAT via npm postinstall • C2: sfrcl*k.com (see threat feed, screenshot #2👇) The main takeaway, is that in a few days: • CVE will be assigned • scanners will alert But the attack already ran. Most tools detect known issues. Runtime + baselining detects unknown behavior, before it has a name. If you want to check this in your environment, happy to help, reach out to me any time. Another gem from our amazing Research & MDR teams, led by Dan Yahav Omer Idel Moshe Hassan Eldan Talis Upwind Security
-
Amiram Shachar reacted on thisAmiram Shachar reacted on thisEarly adopters. Always. 🏓 My highlight of the week happened today, meeting the Ping Identity Cybersecurity leadership in Florida ahead of the matza balls 🫓 PingIdentity, with Russ, Kris, Jack and team, have been true early adopters and design partners, helping us shape and implement our inside-out approach from day one. Russ K. & Dr. Jack Whitter-Jones thank you for an amazing day. Kris Paterson - you were missed mate. P.S. - Upwind’s native integration with Ping Identity and PingOne enables real-time correlation of IAM risk directly within your cloud providers to PingOne identities.
-
Amiram Shachar reacted on thisAmiram Shachar reacted on thisThe best way to abuse the RSA jet lag is to discover a supply chain attack in production affecting multiple customers. Details will be shared soon 🏄♂️ Dan Yahav Omer Idel what an outstanding work! Please note that the timestamps in the screenshots are shown in GMT+3, which is equivalent to late 30.03 ET
Experience & Education
-
Upwind Security
********** * ***
-
******
**** ********* * ******* ******** **** ** ******
-
*******
******* * ***
-
*** ******* ** ********** ******** *******
******** ** ******* ***** ******** ******* undefined
-
View Amiram’s full experience
See their title, tenure and more.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
or
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Projects
-
Pangea
-
Pangea is a highly scalable platform helping marketers to take control, manage, and optimize ad campaigns on top of Facebook Ads API.
Using real time user analysis and dynamic content creation, the platform provides marketers with advanced insights for massive campaign management and focuses on delivering optimal results.
The Pangea platform supports marketers with automatic marketing decisions and increases the efficiency of their media Ad Spending, thanks to our automatic optimization…Pangea is a highly scalable platform helping marketers to take control, manage, and optimize ad campaigns on top of Facebook Ads API.
Using real time user analysis and dynamic content creation, the platform provides marketers with advanced insights for massive campaign management and focuses on delivering optimal results.
The Pangea platform supports marketers with automatic marketing decisions and increases the efficiency of their media Ad Spending, thanks to our automatic optimization tools and massive scalable enabling functionalities, which are designed based on the best practices and know-how.Other creators
Recommendations received
1 person has recommended Amiram
Join now to viewView Amiram’s full profile
-
See who you know in common
-
Get introduced
-
Contact Amiram directly
Other similar profiles
-
Janakan Rajendran
Janakan Rajendran
RunLoyal - All-in-One software to run your Pet Business / iTrustPRO
9K followersAtlanta, GA
Explore more posts
-
Hang H.
InsForge • 3K followers
Happy new year! Quick update for things we've shipped at InsForge in last month (Dec 2025) 👇 1. Multi region deployments in US East, US West, EU Central, AP Southeast 2. Direct Postgres access with a standard connection string for any client or external service 3. Apple OAuth support added to InsForge Auth 4. Alipay payments now supported for subscriptions. 5. Expanded MCP installer with support for GitHub Copilot and Qoder 6. Realtime module built on WebSockets with pub sub, message history, and RLS 7. Official Next.js support for InsForge Auth components 8. First party Zeabur integration 9. PGVector enabled by default for vector store 10. Hit 1K stars on GitHub thanks to the community ⭐️
29
1 Comment -
Mindy Ferguson
9K followers
🐰 🐰 🐰 We are excited to share that Amazon MQ now supports Graviton for RabbitMQ! RabbitMQ clusters running on M7g instances deliver up to 50% higher workload capacity and up to 85% higher throughput over comparable Amazon MQ for RabbitMQ clusters running on M5 instances. 🐰 🐰 🐰 #Day1 #AWS #AmazonMQ #MQ #RabbitMQ #Messagebrokers #Messaging https://lnkd.in/gNT5R_PV
48
-
Trunal B.
Clazar • 10K followers
I just posted about how migration has become the wedge for transformation on AWS. The natural next chapter after that is Gen AI. Ruba Borno even underscored it by calling GenAI the top priority for AWS partners. And AWS has formalized this with the Generative AI Competency. It’s no longer enough to spin up a flashy demo. Customers want proof you can take them from PoC to production impact. Here’s my perspective… AI capability is now level 1. The real differentiator is AI competency… the ability to operationalize it, tie it to business outcomes, and make it repeatable across customers. That’s the new trust marker. 👉 For those leaning into GenAI, how are you showing customers that you’re not just experimenting, but ready to deliver at scale? This is exactly the kind of shift we’ll be unpacking in our upcoming webinar with Karthik Balakrishnan, Steve Vaughan and Sreejith Karuthody. Join us to explore how partners are building revenue impact by combining marketplace, co-sell, and AI agents. 📅 September 16, 10 AM PT. 🔗 https://hubs.ly/Q03CwDwH0
16
-
Komodor
12K followers
Komodor VP of Product, Aviv Shukron was recently interviewed on KubeFM about Kubernetes autoscaling solutions, where he shared his perspective on the current landscape of scaling tools. We discussed the various options available today, from traditional open-source solutions like Cluster Autoscaler to newer tools like Karpenter, as well as commercial offerings like Spot.io. Aviv emphasized that efficiency should be the ultimate deciding factor when choosing between these solutions. Based on experience, Aviv highlighted how Karpenter performs as well as commercial solutions while offering a more dynamic approach to scaling and enabling proactive decision-making. Aviv notes that Karpenter has become his preferred choice for Kubernetes auto-scaling implementations.
15
-
Enis Hulli
e2vc • 41K followers
I love the way Ozgun puts it: Ubicloud is an open-source alternative to AWS, at a fraction of the cost How do they dare take on these cloud giants? Özgun shares the backgrounds of the founding team (Daniel and Umur) and what it really takes to go head to head with big tech More videos from e2vc Summit!
64
1 Comment -
Ozgun Erdogan
6K followers
Today, we're excited to announce Ubicloud PostgreSQL v2: Seven new features, higher performance! https://lnkd.in/eTDxw4bc How is this different than other managed Postgres solutions? 1. We use local NVMes. This helps us deliver price-performance that's 7.9 - 11.1x better than Aurora Postgres. 2. Our team has years of experience with Postgres. This makes us keep reliability as a forethought. 3. Ubicloud provides the first open-source solution for managed Postgres. This keeps you in control of your database. If interested, check out our v2 and tell us what you think! ⬇️⬇️⬇️
77
2 Comments -
Michael Holdmann
PraSaga Foundation • 6K followers
Aptos ↔ SagaChain™ PraSaga™ Foundation is excited to share sample bridge contracts that demonstrate how Aptos can connect to SagaChain via SagaInterop™. What this means: 🔹Developers can see how SagaPython™ call-data flows into Aptos and emits logs for a SagaChain relay. 🔹This is exploratory code for learning and experimentation — not yet production-ready. 🔹The goal is to engage the Aptos Foundation and developer community to test, give feedback, and co-create interop standards. Code is open and live on Public Development Testnet: https://lnkd.in/gsiCYgkZ We’d love to hear from Aptos builders and collaborators interested in extending their dApps with persistent-state data management and SagaPSA™ (Programmable Smart Assets). #Aptos #SagaChain #SagaInterop #Web3Interop #BlockchainInnovation #SagaTechStack
10
1 Comment -
Evan Boyle
GitHub • 4K followers
Today we're launching a developer preview of GenSX Cloud: infrastructure designed for agents. https://lnkd.in/gdbaCUBX Most serverless platforms cap at 5-15 minutes. We give you 60 minutes — an order of magnitude longer. Why? Because AI agents easily take multiple minutes to run. No more replatforming when you hit those artificial limits. Full Node.js runtime included. One command deployments 🚢 - Generated REST APIs for sync/async endpoints - Realtime streaming - Consumable via built-in MCP server Dynamic agent storage ⚡ Primitives for blobs, vector search, and SQL databases. All of this can be provisioned at runtime in just a few milliseconds, meaning that agents can create their own storage on the fly as they need it. We've solved the hard infrastructure problems so you don't have to. The future of AI isn't just about better models—it's about enabling engineers to build reliable applications with them. Give GenSX Cloud a try today!
26
1 Comment -
Priyank Dhami
Vantara • 1K followers
Kubernetes cost optimization is more than just monitoring - it’s a strategy. This article compares Kubecost and OpenCost, helping you choose the right fit for your enterprise cloud setup. A must-read for DevOps, FinOps, and platform teams 🔗 Read here: https://lnkd.in/ddKzbkTe #Kubernetes #FinOps #DevOps #CloudCost #PlatformEngineering #PlatformEngineers
5
-
Carlos Delatorre
Saris AI • 9K followers
From Kubernetes diffs and ECS weighted traffic shifting to Terraform auto-approvals and GitOps enhancements, we packed Q1 with powerful CD platform upgrades. Highlights include: ✅ Namespace enforcement for Kubernetes & Helm. ✅ Blue-Green weighted traffic for ECS. ✅ Git-triggered pipelines in GitLab. ✅ Environment-type-based freeze windows. ✅ API-driven observability. 👉 Dive into what’s new: https://lnkd.in/dKGG3h95
24
-
Sam Bhagwat
Mastra • 50K followers
Introducing Mastra Storage 🚀 Building AI apps? Data management gets complex fast. You need to handle: • Conversation histories across multiple turns • Workflow states • Evaluation metrics • Monitoring data Mastra Storage solves this. It’s easy to use when starting and also when scaling. Here’s what it manages: 📝 Memory: Organize conversation threads with resource IDs 🔄 Workflow: Pause and resume complex states 📊 Evaluation: Track performance metrics 🔍 Observability: Debug with OpenTelemetry traces We have flexible database options: - Start with LibSQL (built-in) - use Postgres in production - or use other providers such as Upstash or Clickhouse. Your interface stays the same. Blog post link in comments!
73
14 Comments
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content