Dispatches from Mission Control

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Democratizing Graph-Based Security: Introducing Starbase

Security is a basic human right, but many security teams struggle to answer even seemingly basic questions about attack surface or blast radius due to poor visibility

Austin Kelleher
Feb 23rd, 2022
  • CSPM
  • CAASM
  • SecOps
Does Your CAASM Tool Capture Transitive Risk? It Really Should.

You are likely familiar with the cybersecurity adage: “You can’t protect what you don’t know about.” It’s common-sense enough wisdom, but if we’re being honest, we

Erich Smith
Feb 16th, 2022
  • CAASM
J1 Spotlight: Patricia Arnedo, Software Engineer

Individuals in STEM are often described as innately methodical, detail-oriented, and curious. However, their creative, artistic qualities are the ones that make them

Tanvi Tapadia
Feb 14th, 2022
JupiterOne Press Releases New Book: Cyber Defense Matrix

In a world where cybersecurity threats evolve and proliferate at dizzying speed, a confusing and disordered cybersecurity landscape makes it all too difficult to

Sounil Yu
Feb 10th, 2022
  • CAASM
  • GRC
  • SecOps
Building a Healthy Cybersecurity Culture

Every company has a workplace culture and a security culture. Many people would define the former as “flexible PTO and cold brew on tap” (which, of course, is a gross

Caroline Wong
Feb 9th, 2022
Case Study: Auth0 Reduces Third-Party & Cloud Asset Risk with JupiterOne

Auth0 helps enterprise companies solve the most complex, large-scale identity use cases with its extensible and developer-friendly solution. To get to that level of

Jennie Duong
Feb 8th, 2022
  • CAASM
  • SecOps
How JupiterOne's Security Team Manages "Meeting Evidence" as Code

If you’re anything like me (which I hope you’re not), or let’s say if you’re anything like my mind, you spend 75% of your time overthinking. You reach for the closest

Yvie Djieya
Feb 7th, 2022
  • SecOps
JupiterOne Takes Home the Gold in Cybersecurity Excellence Awards

We are honored to announce our company founder and Chief Executive Officer Erkang Zheng, named as Cybersecurity CEO of the Year-North America by the Cybersecurity

Melissa Pereira
Feb 4th, 2022
Introducing Compliance 2.0 - Compliance is the Byproduct of Great Security

Many companies invest in compliance activities to follow various laws and regulations but not necessarily to improve their overall security posture. Whether you are

Jennie Duong
Feb 3rd, 2022
  • GRC
The OWASP Podcast: New Ideas. New Voices. New Hosts.

Eight years ago I took over the OWASP Podcast from Jim Manico, originator of the project. In that time 160 episodes have been published, with over 500,000 downloads

Mark Miller
Feb 2nd, 2022
2022 Lunar New Year Video Greeting from Erkang Zheng

As we prepare to celebrate Lunar New Year, we offer you a personal story of what the new year tradition means to Erkang Zheng, CEO of JupiterOne.

Erkang Zheng
Jan 31st, 2022
CAASM for the Blue Team

Recently, life has been chaotic. For two years, events have shattered our perspective on what work, health, and community means to us. As we try to sleep through this

Chasen Bettinger
Jan 27th, 2022
  • CAASM
  • CSPM
A Data Privacy Day Call to Arms: The Shared Responsibility to Protect Customer Data

Today, millions of people worldwide are becoming aware of how their personal data is collected, shared, and monetized in our modern digital economy. Studies show that

Melissa Pereira
Jan 27th, 2022
  • CAASM
  • CSPM
  • GRC
Introducing the AskJ1 Community

If you couldn’t tell from the video, we are so excited to launch the AskJ1 Community! By bringing together our users, team, and security professionals at large, we’re

Ashleigh Lee
Jan 24th, 2022
Red Team, Go!

As we continue to build our security teams at JupiterOne, we asked Kenneth Kaye, Security Automation Architect, to describe our Red Team approach, and Chasen

Kenneth Kaye
Jan 20th, 2022
  • CSPM
  • SecOps
J1 Spotlight: Kenan Warren, Principal Software Engineer

Engineers are the individuals who sit in the magical area between an exciting idea and a promising product in any organization. JupiterOne is lucky enough to have

Tanvi Tapadia
Jan 18th, 2022
25 On-Point Cybersecurity Conferences in 2022

Most security practitioners admit they spend their free time upskilling. Learning can occur in settings ranging from the practitioner’s home labs to security

Jasmine Henry
Jan 12th, 2022
Book Preview: What is a Modern Cyber Asset

On October 19, 2021, we published the book, "Modern Cybersecurity: Tales from the Near-Distant Future". This is an excerpt from a chapter by Sounil Yu.

Sounil Yu
Jan 11th, 2022
  • CAASM
  • SecOps
Podcast:  The InfoSec Color Wheel with Jasmine Henry

We’ve all heard of “Red Teams” and “Blue Teams” when it comes to cybersecurity. But what about the “Purple Team”, the “Yellow Team” or the “Blue Team”. What are those

Mark Miller
Jan 10th, 2022
Rapid Response: Finding NPM libs 'colors' and 'faker'

On January 9, 2022, journalist and researcher Ax Sharma wrote an article, "Dev corrupts NPM libs 'colors' and 'faker' breaking thousands of apps".

JupiterOne Team
Jan 10th, 2022
The 5 Most Common Questions About Cyber Asset Management

The cybersecurity forecast for 2022: More of the same—only worse. Yes, the sophistication of cyberattacks is growing by the minute. Unfortunately, so are the rewards

Jennie Duong
Jan 5th, 2022
  • CAASM
  • CSPM
Best of 2021 - Downloads and Resources

It's that time of year where I poll my friends to see what kind of cool downloads and resources they found in 2021. Hopefully, you'll see something you like.

Mark Miller
Jan 4th, 2022
Book Preview: Preparing your organization to adopt a security practice

On October 19, 2021, we published the book, "Modern Cybersecurity: Tales from the Near-Distant Future". This is an excerpt from a chapter by Yolonda Smith.

Yolonda Smith
Jan 3rd, 2022
  • CAASM
  • SecOps
The Top 5 JupiterOne Articles from 2021

JupiterOne published hundreds of blog articles in 2021, including some by our friends in the community. We checked to see how the community voted "with its eyes" this

Mark Miller
Dec 29th, 2021
Understanding Suspicious Updates to AWS Managed Policies

As you stand knee deep in the water watching waves form, you set your sights on the perfect one to ride into shore. “This is it!”, you think. “It’ll carry me to shore

Chasen Bettinger
Dec 28th, 2021
  • CAASM
  • SecOps
Log4Shell Remediation Visibility with JupiterOne and Log4Shell_Sentinel

If you’re neck-deep in Log4Shell remediation and wanting the assurance of an automated process to ensure your hosts are patched and stay patched, the following

Erich Smith
Dec 27th, 2021
Potential CloudFront/S3 takeover risks

We recently helped a customer identify some potential CloudFront/S3 takeover risks. You can find the details of the risk described in the article, "Simple Route53/Clo

Erkang Zheng
Dec 23rd, 2021
  • CSPM
  • CAASM
  • SecOps
The Debate: Should You Build or Buy CAASM?

Should you build or buy a CAASM solution? It’s a valid question, especially in an ecosystem rich with open source and low-cost security tools. You don’t need

Jasmine Henry
Dec 21st, 2021
  • CAASM
Lessons from Log4Shell: Mapping Code Dependencies and Investigating Code Deployments

Let me open by saying that If you are currently remediating the Log4Shell vulnerability in your environment, this article is not designed for you, although some thing

Akash Ganapathi
Dec 20th, 2021
  • CAASM
CAASM Should Be an Early Security Investment in Every CISO's Playbook

It’s possible to improve your security posture on a shoestring budget. There are a growing number of open source tools for security and compliance, but there are also

Jasmine Henry
Dec 15th, 2021
  • CAASM
Rapid Response: Search for malicious discord tokens in the npm repository

Detect and respond to malicious Discord tokens in npm packages. Learn proactive security measures to protect your development environment.

JupiterOne Team
Dec 14th, 2021
Book Preview: Metrics that Matter - The business context of cyber risk management

On October 19, 2021, we published the book, "Modern Cybersecurity: Tales from the Near-Distant Future". This is an excerpt from a chapter by Keyaan Williams.

Keyaan Williams
Dec 13th, 2021
  • CAASM
Book Preview: Reinventing the Cybersecurity Workforce

On October 19, 2021, we published the book, "Modern Cybersecurity: Tales from the Near-Distant Future". This is an excerpt from one of the chapters.

Sushila Nair
Dec 9th, 2021
Why I Quit Being a JupiterOne Customer...

Over the past 19 months, I was empowered to create a security and compliance function at a Seattle startup. I was a pretty successful Security Director by most

Jasmine Henry
Dec 7th, 2021
JupiterOne Wins Start-up of the Year at BIG Awards for Business

The Business Intelligence Group’s annual BIG Awards for Business results are in and we are so excited to share that JupiterOne has been recognized as “Start-up of the

JupiterOne Team
Dec 7th, 2021
Podcast: Talking about CAASM and Community

Christian Buckley from the CollabTalk Podcast reached out to me to discuss building communities, given my involvement in supporting massive initiatives within

Mark Miller
Dec 3rd, 2021
  • CAASM
A Nation State Attack Surface: Software Supply Chains

Today’s digital supply chains are a continuously growing and dynamic ecosystem of web-based services, applications, and IT assets. These ecosystems are enabled by an

Hema Nair
Dec 1st, 2021
  • CAASM
  • SecOps
The Future of Compliance is Continuous

The future of compliance is continuous. Since the beginning of technology auditing, auditors have had to rely upon spot-checking to validate whether the entity being

Kenneth Kaye
Nov 24th, 2021
  • CAASM
  • GRC
  • SecOps
Book Preview: Knowledge without Action is a Wasted Opportunity

On October 19, 2021, we published the book, "Modern Cybersecurity: Tales from the Near-Distant Future". This is an excerpt from one of the chapters.

Jennifer Czaplewski
Nov 23rd, 2021
Top 5 Reasons Your Attack Surface Is Growing Along with Your Cyber Assets

It’s a good time to be a hacker. Evolving IT architectures and workplace models now offer more entry points than ever for an attack, while simultaneously making it

Jennie Duong
Nov 18th, 2021
  • CSPM
  • CAASM
  • GRC
  • SecOps
Infographic: The State of Cyber Asset Management

Cyber asset management is now a critical component of an organization’s cybersecurity hygiene and posture management. The more cyber assets in an organization’s

Jennie Duong
Nov 18th, 2021
  • CAASM
  • CSPM
  • SecOps
J1 ​​Rapid Response: MacOS Zero-day and water-hole attack. Are you vulnerable? How to tell in minutes.

Zero-day vulnerabilities are the ones that place the most stress on every security team, regardless of the size of the organization. Watering-hole (also known as

Kenneth Kaye
Nov 17th, 2021
  • CAASM
Cisco and JupiterOne Partnership Goes Beyond Traditional Cloud Security

Fireside chat: Cisco Sr. Director of Product Management for Cloud Security Munawar Hossain, JupiterOne CEO Erkang Zheng and CMO Tyler Shields discuss the new partners

Erkang Zheng
Nov 15th, 2021
  • CSPM
  • CAASM
Network Segmentation, Visibility and Third-Party Risk Assessment

When Colonial Pipeline CEO Joseph Blount testified before the US Congress, he revealed that the attack was completely avoidable; Blount admitted that Darkside gained

Steve King
Nov 10th, 2021
  • CAASM
  • SecOps
Book Preview: Hardening the Value Stream by Bryan Finster

On October 19, 2021, we published the book, "Modern Cybersecurity: Tales from the Near-Distant Future". This is an excerpt from one of the chapters.

Bryan Finster
Nov 3rd, 2021
  • SecOps
GitHub Secrets Management with JupiterOne

JupiterOne recently added support for ingesting GitHub Org, Repo, and Environment secrets.

Erich Smith
Oct 27th, 2021
  • CAASM
Book Preview: Modern Cybersecurity, Preface

On October 19, 2021, we published a book, "Modern Cybersecurity: Tales from the Near-Distant Future". Over the next few weeks, we'll be publishing excerpts from the

Erkang Zheng
Oct 20th, 2021
  • CSPM
  • CAASM
Book Release: Modern Cybersecurity - Tales from the Near-Distant Future

The speed of change and the tools of adversaries make it extremely hard to envision a long-term, executable vision for the future of security. However, without ponder

Mark Miller
Oct 19th, 2021
  • CAASM
Our Company Retreat: Camp JupiterOne

Team retreats are an excellent way to bring a company together. For a remote-first company like JupiterOne, I’d say they are essential. It is a great way to strengthe

Melissa Pereira
Oct 18th, 2021
Google Cloud Storage Access Analysis

Identity and Access Management (IAM) for Google Cloud uses IAM Role Bindings, which link three constructs together

Michael Knoedel
Oct 14th, 2021
  • IAM
How To Get Started With IT Security Policies and Procedures

You open your email and there it is. Finally, the company that you really wanted to work for has extended you an offer. You feel a rush of adrenaline as you open it

Jeffrey Lee
Oct 13th, 2021
  • GRC
Top 5 Lessons in Building and Scaling Cybersecurity at a Cloud-Native Startup

I’m the Director of Cybersecurity at Esper, a cloud-native startup that offers powerful cloud tooling for Android device deployment and application management at scal

Jasmine Henry
Oct 12th, 2021
  • GRC
JupiterOne Customer Q&A Spotlight Series: Jasmine Henry, Director of Cybersecurity at Esper

Our customers are at the core of everything we do at JupiterOne. And every security strategy and journey is different for every customer. JupiterOne is starting a mon

JupiterOne Team
Oct 5th, 2021
Boardroom Conversations on Security: Part 7

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation b

Mark Miller
Oct 4th, 2021
JupiterOne is a Finalist for NC Tech Cybersecurity Award

We’re honored to share that JupiterOne has been recognized for its innovation, excellence, and growth as part of the 2021 NC TECH Awards program. JupiterOne is a fin

Melissa Pereira
Sep 29th, 2021
J1 ​​Rapid Response: Another Google Chrome Zero-Day exploit and How to Determine if You're Affected

Last week, we published an article on a recent Chrome zero-day exploit (worth reading if you want see the history of the issue). There was a new announcement this

Sounil Yu
Sep 27th, 2021
  • CAASM
Boardroom Conversations on Security: Part 6

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation b

Mark Miller
Sep 27th, 2021
Future of Cloud Security - Cyber Security Summit Charlotte

In this panel originally recorded for CyberSecurity Summit 2021 in Charlotte, speakers from JupiterOne, Gigamon, Duo Security, Sonatype, Vectra and Center for

Akash Ganapathi
Sep 23rd, 2021
  • CSPM
  • CAASM
2 Attack Vectors are Forcing Changes in how to Secure Software

Cyber criminals have upped their game in the past two years to take advantage of a world distracted in its battles with a global pandemic. Cybercrime is growing conti

Hema Nair
Sep 22nd, 2021
Boardroom Conversations on Security: Part 5

Boardroom Conversations on Security is an ongoing series on how to discuss and present cyber security concerns to your board. It comes from an extended conversation

Mark Miller
Sep 20th, 2021