Shining a Spotlight on Podcasts

As we near the end of 2021, it is interesting to note that there are currently over two million podcasts and over 48 million podcast episodes. Those numbers are incredible on their own, but when you realize that just 4 years ago, there were “only” a little more than half a million podcasts, the growth is astonishing. Those numbers might make you think that the podcast market is saturated, but that is definitely not the case. 

The growth of available podcasts is driven by the increase in interest. More and more people are tuning in to the phenomenon as they explore the vast podcast topics available to them.

Despite the number of podcasts being broadcast today, there is still plenty of room for newcomers to the market. Just as there are many websites for every imaginable interest, there’s room for podcasts in even the tiniest of niches. 

To prove this point, we’ll highlight some of our favorite podcasts hosted right here on WordPress.com. What? You didn’t know you could host a podcast on WordPress.com? Well, pull up a chair and check this out. You might find a new fave podcast of your own, and better still, you might even find some inspiration for creating a podcast yourself! Let’s go!

A Podcast for Every Interest

Obviously, we can’t list the millions of niches here, but we can showcase a few that range across a broad spectrum of interest. Here are 7 that have caught our attention here on WordPress.com.

Love to Sew

If you totally relate to the title of this podcast, then you should tune in. The hosts of Love to Sew, Helen and Caroline, are active members of the sewing community. They understand the need to connect and bring that understanding to each episode. In their words…

“Our episodes are a mix of technical sewing advice, inspirational storytelling, unpacking feelings around sewing and creating, and loads of words of encouragement.”

The Purple Rock Survivor Podcast

Billed as the “The smartest, funniest, most humble, and best Survivor podcast on the internet,” this podcast focuses on discussions of the hit television show “Survivor”. The hosts, John and Andy, along with frequent guest hosts, debate the latest Survivor episode antics each week. As all great armchair quarterbacks do, they use their stellar 20-20 hindsight to diss players, alliances, and the various decisions that caused the latest player to get booted off the show. If you’re a fan of the show, you’ll feel right at home listening to this podcast.

The Premier View Tipperary GAA Podcast

The perfect example of targeting a seriously narrow niche, this podcast brilliantly focuses on topics most people may not know exist. These topics include Tipperary GAA, Club and County, Hurling, Gaelic Football, Ladies Football and Camogie. If you’re like me, you’ve possibly heard of Hurling (the sport), and can probably guess at what Gaelic and Ladies Football is all about, but in most parts of the world, you may not know a thing about GAA, Club and County, or Camogie. I think it’s fair to say, however, that the people who DO know what those sports are all about, are probably thrilled to know that there is a podcast out there that caters just to them.  For the rest of us, let’s just simplify and call it “various sports that are local to a specific Irish region”. If you’re into these sports, or just curious, hurl yourself into a comfy chair and get your listen on.

The New Home Owner Podcast

Targeting a specific group of people, new homeowners, this podcast delivers tips and advice surrounding the entire new home building process – from signing contracts to adding the final finishing touches. This is a great example of how a brick-and-mortar business can share its expertise with visitors, while potentially acquiring new clients. When people acquire valuable information from a business, they inherently trust that business a little more than before. Building trust is a great way to convert visitors into clients. 

Sneaker History

Did you know that there is a passionate sneaker community out there? Sneakers have a history and have become a part of pop culture. This podcast’s goal is to “make a positive impact on the sneaker community, culture, and business of sneakers by telling the stories of the people that make this passion enjoyable”. Episodes are gated, meaning you must be a paying member to access them, but if you’re a sneakerhead, this won’t deter you. And if you are just interested in starting your own podcast, your ears will perk up to know that podcasts can be monetized like this. Nice, right?

Travel Babies

No, this podcast doesn’t focus on babies at all. It is an adventure-filled look at the experiences of two sisters traveling the world. You’ll get their expert take on all things travel, including tips and tricks for making your worldwide jaunts much more enjoyable. “Each week they talk about important travel topics to help you decide when, where, and how to explore the world in style.”

Kyla Marie Charles MomChat Mondays

If you were bummed that the Travel Babies podcast wasn’t about babies, never fear, MomChat Mondays has you covered. Their own description says it best. “A LIVE #MomChatMonday hosted by Kyla Marie Charles and Amy Eilers of House of Eilers bringing all sorts of moms together to chat about motherhood topics from mundane to controversial. No shame, no judgement, just talking with mom friends and figuring it all out as we go– as moms do!”

Of course, these 7 podcasts are just a smattering of cool audible content available on WordPress.com. So tell us, have you ever thought about hosting your own podcast? If so, we have lots of tips and advice to help you succeed. You can start with a few of the posts we’ve shared on the subject, including:

WordPress.com’s Podcasting for Beginner’s CourseWhy Launch a Podcast with a WordPress WebsitePodcast Equipment You NeedPodcast Marketing StrategySEO for Podcasts: 5 Ways to Get More Listeners4 Tips for Building a Podcast BrandPodcasts and Creators: Earn Money with Payments

We’ve shown how diverse podcasts can be, but it’s more than just topic diversity that sets a podcast apart. If you are considering starting a podcast, there are some other aspects to consider.

Types of Podcasts (Make It Yours)

No matter the topic, there are various ways to format or organize your podcast. Some subjects lend themselves more closely to one or another way, but many topics are open to multiple presentation formats. Consider the following formats to determine which might work best for you and your topic.

Interviews – Some podcasts primarily center around interviews with either famous people or topic experts. Conversations or Roundtable – In industries where change happens frequently, podcasters often choose a roundtable or conversational format. This style provides a group of hosts, who often know each other well, a chance to converse about trending news or perhaps even a bit of industry gossip. Monologues – Subject matter experts frequently use this format to inform or teach the audience about various aspects of the niche topic.Storytelling or Theatrical – Rather than conversations, these podcasts are performances. The storytelling format usually involves one host reading chapters or episodes of a story, interspersed with commentary. True crime stories fit this model well. A podcast with a theatrical format is usually a full-blown production with multiple voices/actors. These are like plays, without the visuals.

Of course, some podcasts might be a mix of the above formats from episode to episode, but the most successful will likely stick pretty closely to one format. This consistency provides your audience with a familiar sense of place. Suppose someone enjoyed a storytelling type of format in one episode. In that case, they’d likely hope to experience more of the same in future episodes.

Podcaster Personality Styles (Be Yourself)

Once you’ve figured out the podcast’s topic and style, there’s one more crucial element – you! Great content, told in an interesting format, is lovely, but in the end, it’s your personality that people really want to connect with. Don’t let that worry you. If you weren’t the most popular kid in the class, that wouldn’t stop you from connecting with an audience with your own personality brand. Let’s take a quick look at some examples.

We’ve seen that some topics work better with certain formats than with others, and the same can be true of personalities. A monologue podcast focused on teaching the fine details of investing might not work as well with a goofy personality type. Then again, that odd combination might actually be a huge winner. Who knows? But for most podcasts, matching the topic with an appropriate format and personality type makes the most sense.

A few typical personality types include:

SeriousInformativeCasual, fun, and goofyComedic

Casual, fun types work well for entertainment topics. Serious types match well with true crime storytelling, for example, and informative, no-nonsense types click with business or educational topics. You know your topic and your personality best. Find the sweet spot that makes sense to you, and it will likely appeal to others as well.

So let’s put all of this together. Follow our recipe for podcasting success but feel free to throw in your own “seasoning” to truly make it yours.

A Recipe for Podcasting Success

Join Our Podcasting Course!

If you’ve ever wanted to start or grow your podcast, we have a new course designed just for you! Gain all the fundamental (and a few advanced) skills you need to create a podcast you’re proud of. Easily digestible, go-at-your-own-pace lessons, taught by some of the most seasoned podcasters on the internet, will challenge you and help grow your confidence — until you’re a podcasting pro!

Join Podcasting for Beginners

Quelle: RedHat Stack

Mirantis Kubernetes Engine 3.5 Release

We are pleased to announce the availability of Mirantis Kubernetes Engine 3.5, with key enhancements including: Standard OIDC support for single sign-on More efficient installation footprint Improved ease of use Simplified lifecycle management for Swarm users Support for massive clusters with high traffic throughput requirements Enhanced support options through Mirantis OpsCare In this post, we’ll … Continued
Quelle: Mirantis

Security Command Center – Increasing operational efficiency with new mute findings capability

Security Command Center (SCC) is Google Cloud’s security and risk management platform that helps manage and improve your cloud security and risk posture. It is used by organizations globally to protect their environments providing visibility into cloud assets, discovering misconfigurations and vulnerabilities, detecting threats, and helping to maintain compliance with industry standards and benchmarks. SCC is constantly evolving, adding new capabilities to make your security operations and management processes more efficient. To help, we’re excited to announce a new “Mute Findings” capability in SCC that helps you more effectively manage findings based on your organization’s policies and requirements. SCC presents potential security risks in your cloud environment as ‘findings’ inclusive of misconfigurations, vulnerabilities, and threats. A high volume of findings can make it difficult for your security teams to effectively identify, triage, and remediate the most critical risks to your organization. In these cases, you may wish to tune the incoming volume of findings, as some findings may not be relevant for a given project or organization based on your company’s policies or risk appetite. This mute findings capability enables organizations to make Security Command Center findings more reflective of their particular risk model and prioritization.  Enabling operational efficiencies for your securityWith the launch of ‘mute findings’ capability, you gain a way to reduce findings volume and focus on the security issues that are highly relevant to you and your organization by suppressing findings that fit certain criteria. It saves you time from reviewing or responding to findings that you identify as acceptable risks within your environment. For example, alerts for assets that are isolated or fall within acceptable business parameters may not need to be responded to immediately or remediated at all.Once muted, findings continue to be logged for audit and compliance purposes, and muted findings are still available for review at any time. However, they are hidden by default in the SCC dashboard and can be configured to avoid creating pub/sub notifications, allowing your teams to focus on addressing issues highlighted by non-muted findings.  Sample Use Cases for muting findingsThe following are a few sample use cases or scenarios in which the new mute findings capability can be helpful:Assets within non-production environments where stricter requirements may not be applicable.Recommendations to use customer-managed encryption keys in projects that don’t contain critical data.When granting broad access to a datastore, which intentionally is open to the public in order to disseminate public information.Findings not relevant to your organization based on your company’s security policies.How to mute findings in SCCWith this release, SCC findings now have one of the following three states:Muted – Findings that have been either manually muted by a user or automatically muted by a mute ruleUnmuted – Findings that have been unmuted by a userUndefined – Findings that been never been neither muted nor unmutedYou can quickly set this up for your Google Cloud environment and take advantage of this capability: 1: Automatically mute findings using mute rulesMute rules enable you to scale and streamline your security operations process by automatically muting findings. You can create mute rules in SCC to silence findings based on criteria you specify. Any new, updated, or existing findings are automatically muted if they match the mute rule conditions.2. Manual option to mute findingsThe manual option enables you to review and silence individual findings. You can select one or more findings in your findings view and manually mute them.3. Unmuting findingsAs your organization policy changes, there maybe scenarios where you would want to unmute findings that have been silenced in the past. For findings that have been muted either by a mute rule or manually earlier, but are now important for your environment, you can simply unmute them in the findings view. Once unmuted, they remain in that state and will not be automatically muted again by any mute rule. However, you can use the manual option to mute them again.4. Auditing mute operationsThere are two additional attributes ‘mute initiator’ and ‘mute update time’ available in the findings. These attributes store the information on which mute rule or user took the mute/unmute action, along with a timestamp when the action was taken, providing you visibility for future auditing and investigation.5. Findings viewThe findings view in SCC provides a consolidated view of findings across threats, misconfigurations, and vulnerabilities. Muted findings are hidden in the default view. But to view muted findings, you can quickly and easily click on More Options > Include muted findings.If you wish to see ONLY muted findings, simply add a filter for mute=MUTEDGetting started with muting findings in SCCMute findings functionality is now available in SCC through the Google Cloud Platform console, gcloud tool, and API. You can get started with these new capabilities today using our product documentation.And, you can learn more about using SCC to comprehensively manage security and risk across your GCP footprint in our Getting Started video series.Related ArticleHow Veolia protects its cloud environment across 31 countries with Security Command CenterSecurity Command Center enables Veolia to manage security and risk for their cloud environmentRead Article
Quelle: Google Cloud Platform

Edge computing—building enterprise edge applications with Google Cloud

As we discussed in part 2 of this blog series, if you design your edge computing realistically, your systems may not be connected to the network all the time. But there are a variety of tools you can use to manage those edge deployments effectively, and that can even tie them back into your main environment! In this third blog of the series, we’ll discuss the role of software in edge computing, and Google Cloud’s solutions to this end.Google provides softwareWhen it comes to edge environments, Google Cloud’s role is clear: we treat the edge as the domain of our customers and partners. We do not send remote servers for pickup or preconfigure boxes to sync. Instead, we provide software and tools to configure and maintain all clusters as part of the Anthos suite, combined with Google Kubernetes Engine (GKE) and the open-source Kubernetes. An Anthos cluster at the edge may be a full GKE edge installation or a fleet of microk8s Raspi clusters. As long as the attached cluster is running Anthos Config Management and Policy Controller, the remote cluster may be managed via consistent or intermittent connectivity. In addition, Anthos Fleets facilitates organizing Kubernetes clusters into manageable groups — delineated by cross-service communication patterns, location, environment, and an administrator managing the block of clusters. This is a different approach from other cloud providers who may provide a similar fully managed experience but with proprietary hardware that inevitably leads to a certain level of lock-in. By focusing on the software stack, Google sets the path for long term successful edge fleet management.(As an aside, if you are interested in a fully managed experience, Google partners with vendors who will take the responsibility of managing the hardware and configuration of the Anthos edge clusters.)Let’s look at the various tools that Google Cloud offers and how they fit into an edge deployment. Kubernetes and GKEWhere does Kubernetes fit in? In a nutshell, Kubernetes brings convention.The edge is unpredictable by nature. Kubernetes brings stability, consistency and extends familiar control and data planes to the edge. It opens the door to immutable containerized deployments and predictable operations.Data centers and cloud service providers deliver predictable environments. But the broader reach of the edge introduces instability that platform managers are not accustomed to. In fact, platform managers have been working to avoid instability for the past two decades. Thankfully, Kubernetes thrives in this extended edge ecosystem. Often, in enterprise we think of massive k8s clusters running complex interdependent microservice workloads. But at its core, Kubernetes is a lightweight, distributed system that also works well when deployed on the edge with just a few and focused deployments. Kubernetes increases the level of stability, offers a standardized open-source control plane API, and can serve as a communications or consolidation hub at edge installations that are saturated with devices. Kubernetes brings a standard container host platform for software deployments. A simple redundant pair of NUCs or Raspi racks can improve edge availability and normalize the way our data centers communicate with our edge footprints. AnthosWhat about Anthos? Anthos brings order.Without a good strategy and tools, the edge can be daunting if not impossible to manage cost-effectively. While it’s common to have multiple data centers and cloud providers, edge surfaces can number in the hundreds or thousands! Anthos brings control, governance and security at scale. With Anthos, we overlay a powerful framework of controls that extends from our core cloud and data center management systems to the farthest reaches of your edge deployments. Anthos allows central administration of remote GKE or attached Kubernetes clusters — running private services to support location-specific clients. We see the Anthos edge story developing in all of these industries:WarehousesRetail StoresManufacturing and FactoriesTelco and Cable Providers Medical, Science and Research LabsAnthos Config Management and Policy ControllerConfiguration requirements have advanced in leaps and bounds. Anthos Config Management (ACM) and Policy Controller come to the rescue in these scenarios, enabling platform operations teams to manage large edge resources deployments (fleets) at scale. With ACM, operators create and enforce consistent configurations and security policies across edge installations.Source: https://cloud.google.com/anthos-config-management/docs/overviewFor example, one Google Cloud customer and partner plans to deploy three bare metal servers running either Anthos Bare Metal or attached clusters in an HA configuration (all three acting as both master and worker) at over 200 customer locations. The capacity of the cluster totals to more than 75K vCPU, and they plan to manage the configuration, security and policy at scale across this entire fleet using ACM.Anthos FleetsAs more edge clusters are added to your Anthos dashboard, cluster configurations become increasingly fragmented and difficult to manage. In order to provide proper management and governance capabilities for these clusters, Google Cloud has the concept of fleets. Anthos Fleets negates the need for organizations to build their own tooling to get the level of control that enterprises typically desire, and provides an easy way to logically group and normalize clusters and help simplify the administration and management of these clusters. Fleet-based management is applicable for both Anthos (edge included) and GKE clusters.Anthos Service MeshThe edge is fertile ground for microservices architectures. Smaller, lightweight services improve reliability, scalability and fault tolerance. But they also bring complexity in traffic management, mesh telemetry and security. Anthos Service Mesh (ASM), based on open source Istio, provides a consistent framework for reliable and efficient service management. It provides service operators with critical features like tracing, monitoring and logging. It facilitates zero-trust security implementations and allows operators to control traffic flow between services. These are features we have been dreaming of for years. Virtualizing services decouples networking from applications, and further separates operations from development. ASM together with ACM and Policy Controller is a powerful set of tools to simplify service delivery and drive agile practices without compromising on security. Pushing the edge to the edgeEven though edge computing has been around for a long time, we believe that enterprises are just beginning to wake up to the potential that this model provides. Throughout this series, we’ve demonstrated the incredible speed of change and high potential that edge technology promises. Distributing asynchronous and intermittently connected fleets of customer-managed commodity hardware and dedicated devices to do the grunt work for our data centers and cloud VPCs opens up huge opportunities in distributed processing.For enterprises, the trick to taking advantage of edge is to build edge installations that focus on the use of private services, and designing platforms that are tolerant of hardware and network failures. And the good news is that Google Cloud offers a full software stack including Kubernetes, GKE, Anthos, Anthos Fleets, Anthos Service Mesh, Anthos Config Management and Policy Controller that enable platform operators to manage remote edge fleets in places far, far away!Related ArticleEdge computing—a paradigm shift that goes beyond hybrid cloudEdge platforms are evolving at an incredible speed, opening up opportunities for enterprises. Google tools like Kubernetes, GKE and Antho…Read Article
Quelle: Google Cloud Platform

Empowering DevOps to foster customer loyalty in modern retail with MongoDB Atlas on Google Cloud

Consumer demands are becoming more complex, driven by high expectations for personalized experiences that strike the right chord at the perfect time. One study from McKinsey found thatnearly three-quarters of consumers demand personalization when interacting with retailers.Retailers old and new of any size must embrace the challenges head on and learn to capture customer loyalty. While each business has a unique journey toward modernizing its business, all of them share something in common: Effective approaches to DevOps and data analytics underpin their success.Retailers sometimes struggle to change previous retail models into the much more intimate, personalized, and real-time retail experiences that consumers now want, whether shopping in-store or online. At the same time, retailers and many newcomers are jumping all in, and devising exceptional experiences that transform shopper experiences and elevate expectations even further.MongoDB and Google Cloud have been helping retailers of all sizes better address quickly changing market opportunities. As retailers continue to need more powerful systems of engagement and data analytics, the combination of MongoDB Atlas and Google Cloud solutions offer retailers such as 1-800-FLOWERS.COM, Inc. a solid mix of proven IT infrastructure and expertise.Maximizing data value for developersDevOps is increasingly tasked with creating experiences that will bring customers to a retail website, and guide them through the purchasing process. Along the way, they need to build in steps that keep customers fully engaged in the buying process and discourage things like cart abandonment. A successful build depends a lot on how much quality data is available about customer shopping experiences and how easy it is for DevOps teams to derive insights from that information.Google Cloud is very much a developer’s cloud, and we at MongoDB are very much a developer’s database. We like the breadth of Google Cloud services, which pair well with our products. Our collaboration with Google Cloud feels very natural both in terms of the technology we develop and how we are approaching serving our clients’ needs. Together, we give DevOps teams at retailers a modern toolkit to maximize the value of their work.The cloud-based environment supported by Google Cloud and MongoDB Atlas increases the speed and success of experimentation and ultimately delivers solutions with the greatest impact. With agile environments like ours, teams experiment much faster, leading to more innovative shopping experiences that differentiate a retailer from their competitors.Any cloud solution has to be usable for retailers of all sizes so that they can develop services according to their unique needs, expertise, and visions. The goal should be to empower a retailer’s DevOps team to be as self-sufficient as possible, and not have to rely on a third-party every time changes need to be made.In an industry facing extremely tight margins—and where a two percent efficiency gain or 2x acceleration of time to market can make or break the success of a project—gaining any edge is essential for retailers. Google Cloud and MongoDB provide that edge to retailers, as well as to other companies across industries.Cultivating a vision at 1-800-FLOWERS.COM, Inc.1-800-FLOWERS.COM, Inc. is an exceptional example of what can be achieved when going all in with modern data and DevOps solutions. Chief Technology Officer Abi Sachdeva, has pursued emerging technologies to support its business teams with the latest technologies to drive value for its customers.Abi has been laser-focused on delivering new personalized experiences by continually innovating customer-facing services. Driven by a commitment to foster engagement across its industry-leading brands through a centralized customer experience, 1-800-FLOWERS.COM, Inc. built an e-commerce platform that is inclusive of both products and resources aimed at improving how people express themselves.To best manage all the eCommerce environments associated and ensure outstanding customer service, 1-800-FLOWERS.COM, Inc. with MongoDB and Google Cloud to revolutionize its DevOps.“With the help of MongoDB and Google Cloud, we transformed people, processes, and our technology. It has been a very stable experience requiring little administrative work,” says Abi. “Traditional technologies weighed us down in the past. MongoDB and Google Cloud deliver data models and DevOps solutions that accelerate our development and deployment.”MongoDB Atlas , Inc. with aggregation pipelines and a distributed system design that help it to scale quickly, while Google Cloud made its new approach to agile and DevOps a reality.he speed and agility that come with cloud services, companies like 1-800-FLOWERS.COM, Inc.  keep up with the constantly changing customer preferences. With proven cloud solutions that at once increase overall IT effectiveness and decrease the burdens on IT teams, 1-800-FLOWERS.COM, Inc.  is better positioned to constantly experiment, innovate, and deliver experiences that delight customers.“The fully managed MongoDB Atlas database on Google Cloud has unlocked tremendous potential in our IT architecture,” says Abi. “From agility in scaling and improved resource management to seamless global clusters and premium monitoring, MongoDB and Google Cloud reduce complexity and allow our teams to stay lean and focused on innovation rather than infrastructure.”Looking toward the holidays and beyondThe very same systems that encourage experimentation and innovation can position retailers and other companies to excel in during and long after the holiday season. Companies need elasticity, scalability, and agility to facilitate experimentation and to navigate the turbulent external factors across their marketplace.Every holiday season is challenging for retailers, but current supply chain concerns combined with massive changes to how people shop as a result of the COVID-19 pandemic will make 2021 a particularly important year for the industry. I believe that companies that have increased their backend elasticity and improved their DevOps culture will fare especially well amid the market upheaval.As organizations modernize IT, it will be increasingly important to pair the possibilities of software and infrastructure to enable smaller DevOps teams to act independently and quickly. This improves culture across the business as people are more empowered and supported.In addition, I encourage DevOps professionals to place more importance on understanding customers, business values, and to be people-first in their approaches to work. By combining this level of business experience with great coding skills, smaller teams can bolster a retailer’s performance this holiday season and beyond.We are proud to work with Google Cloud to develop and deliver new ways for DevOps in retail and other industries to experiment, innovate, and deploy groundbreaking experiences that transform how people achieve their goals.To learn more about the future of retail innovation,watch this video featuring members of the 1-800-FLOWERS.COM, Inc., MongoDB, and Google Cloud teams.Related ArticleDelivering smiles and sparking innovation at 1-800-FLOWERS.COM, Inc.See how gift retailer 1-800-FLOWERS.COM, Inc., migrated its customer touchpoints to cloud, including GKE and BigQuery, to build a microse…Read Article
Quelle: Google Cloud Platform

Illicit coin mining, ransomware, APTs target cloud users in first Google Cybersecurity Action Team Threat Horizons report

At Google we have an immense aperture into the global cybersecurity threat landscape and the means to mitigate risks that stem from those threats. With our recently launched Google Cybersecurity Action Team, we are bringing more of our security abilities and advisory services to our customers to increase their defenses. A big part of this is to bridge our collective threat intelligence to yield specific insights, such as when malicious hackers exploit improperly-secured cloud instances to download cryptocurrency mining software to the system—sometimes within 22 seconds of being compromised. This is one of several observations that we have published in the first issue of the Threat Horizons report (read the executive summary or the full report.) The report highlights recent observations from the Google Threat Analysis Group (TAG), Google Cloud Security and Trust Center, Google Cloud Threat Intelligence for Chronicle, Trust and Safety, and other internal teams who collectively work to protect our customers and users.The report’s goal is to provide actionable intelligence that enables organizations to ensure their cloud environments are best protected against ever-evolving threats. In this and future threat intelligence reports, the Google Cybersecurity Action Team will provide threat horizon scanning, trend tracking, and Early Warning announcements about emerging threats requiring immediate action.While cloud customers continue to face a variety of threats across applications and infrastructure, many successful attacks are due to poor hygiene and a lack of basic control implementation. Most recently, our internal security teams have responded to cryptocurrency mining abuse, phishing campaigns, and ransomware. Given these specific observations and general threats, organizations that put emphasis on secure implementation, monitoring and ongoing assurance will be more successful in mitigating these threats or at the very least reduce their overall impact.The cloud threat landscape in 2021 was more complex than just rogue cryptocurrency miners, of course. Google researchers from TAG exposed a credential phishing attack by Russian government-supported APT28/Fancy Bear at the end of September that Google successfully blocked; a North Korean government-backed threat group which posed as Samsung recruiters to send malicious attachments to employees at several South Korean anti-malware cybersecurity companies; and detected customer installations infected with Black Matter ransomware (the successor to the DarkSide ransomware family.)Across these four instances of malicious activity, we see the impact of poorly-secured customer installations. To stop them, we embrace a shared fate model with our customers, and provide trends and lessons learned from recent cybersecurity incidents and close calls. We suggest several concrete actions for customers that will help them manage the risks they face. Vulnerable GCP instances, spear-phishing attacks, patching software, and using public code repositories all come with risks. Following these recommendations can reduce the chance of unexpected financial losses and outcomes that may harm your business:Audit published projects to ensure certs and credentials are not accidentally exposed. Certs and credentials are mistakenly included in projects published on GitHub and other repositories on a regular basis. Audits help avoid this mistake. Authenticate downloaded code with hashing. The common practice for clients to download updates and code from cloud resources raises the concern that unauthorized code may be downloaded in the process. Meddler in the Middle (MITM) attacks may cause unauthorized source code to be pulled into production. Hashing and verifying all downloads preserves the integrity of the software supply chain and establishes an effective chain of custody.Use multiple layers of defense to combat theft of credentials and authentication cookies. Cloud-hosted resources have the benefit of high availability and “anywhere, anytime” access. While this streamlines workforce operations, malicious actors try to take advantage of the ubiquitous nature of the cloud to compromise cloud resources. Despite the growing public attention to cybersecurity, spear-phishing and social engineering tactics are frequently successful, so defensive measures need to be robust and layered to protect cloud resources due to ubiquitous access. In addition to two-factor authentication, Cloud administrators should strengthen their environment through Context-Aware Access and solutions such as BeyondCorp Enterprise and Work Safer.The executive summary of the Threat Horizons report is available here, and the full report goes into greater detail of the current cloud threat landscape and the steps we recommend to reduce those risks, and can be downloaded here.
Quelle: Google Cloud Platform