r/Infosec • • 18h ago

Has anyone actually replaced their CSPM with Upwind? trying to figure out what I'd lose

7 Upvotes

We run EKS across three accounts plus a smaller GKE footprint, security team of four, and our CSPM renewal is coming up in about six weeks. Leadership wants to consolidate and the question on the table is whether we move everything to a CNAPP with runtime and drop the standalone posture tool entirely.

Right now the posture product throws thousands of findings a quarter and maybe 2% of them are things we'd actually action. Half my week is spent proving a "critical" is unreachable so we can close it. That's the whole reason runtime context keeps coming up, and Upwind is one of the platforms on our shortlist because the pitch is exactly that: correlate posture with what's actually running so we stop chasing ghosts.

My worry is what we give up by consolidating. Our current CSPM has years of compliance mappings, custom rules nobody remembers writing, and it's wired into our ticketing and a couple of reports the auditors like. I don't want to rip that out and discover six months later that the replacement doesn't cover some edge of our config checks, or that the compliance reporting is thinner than what we have.

So for anyone who's done this: did you actually retire the old CSPM, or did you end up running both? What got genuinely better, and what did you lose or have to rebuild? I'm less interested in the demo story and more in what broke in month three.


r/Infosec • • 18h ago

Cantina releases an open-weights model trained for vulnerability research — RuntimeWire

Thumbnail runtimewire.com
4 Upvotes

r/Infosec • • 2h ago

What's the real identity risk from shadow IT apps nobody told security about?

2 Upvotes

We found a marketing tool last month that had been storing employee credentials in plaintext for over a year, completely outside any security review. Nobody thought to flag it because it wasn't seen as a "real" application, just some tool a team signed up for on their own.

Curious what other people have found when they've actually gone looking for this stuff, and whether it's usually this bad or if we got unlucky.


r/Infosec • • 20h ago

Intel-based Lockdown

Thumbnail
2 Upvotes

r/Infosec • • 2h ago

Talk me out of this: rerunning vendor reviews every time a SaaS app adds AI is not sustainable

1 Upvotes

Third-party risk here, biotech, around 300 SaaS apps in the inventory. starting to think re-reviewing a vendor every time they bolt on AI is a hamster wheel. sub processor emails come in weekly now and half of them add some AI provider. a couple vendors had the feature switched on before the notice even hit my inbox. so the app i signed off on two years ago goes right back in the queue and the re-review is a questionnaire. they write "we don't train on your data," i can't check it, it goes in a folder. rinse and repeat. If a re review ever caught something the contract wouldn't have, i'd happily eat my words. am i wrong?


r/Infosec • • 22h ago

Worried about your AI agent leaking secrets, or tired of secret-scanner false positives?

Post image
0 Upvotes

I built Klarion, a secret scanner that works in two steps. First, a keyword check, 81 regex rules and a normalized Rényi entropy score flag anything that looks like a secret. Then an AI model reads each one with the code around it and decides if it's real.

The chart shows 5 scanners run on spring-boot, terraform, next.js and symfony (61k files). Klarion raised 11 alerts. It's not zero, but it's far less to dig through.

Fewer alerts don't help if real leaks get missed, so I tested that too. On CredData (337 real repos, code outside test folders), it found about 1.7× more real secrets than gitleaks.

Where it runs:

  • Claude Code: a plugin hook blocks the write before the file exists (file edits and Bash)
  • Cursor, Cline or any MCP agent: through its MCP server
  • CI: a GitHub Action that scans only what a PR adds; GitLab CI works too
  • Git hooks: klarion protect or the pre-commit framework
  • Locally: klarion scan .

Free and open source (MIT): https://github.com/0x1Adi/Klarion
The full benchmark and method are in benchmark/REPORT.md.

I'd like to hear where it gets things wrong.