What is IDOR (Insecure Direct Object Reference)?
IDOR (insecure direct object reference) is an access control flaw that leaks data when apps skip authorization checks. See how IDOR works and how to prevent it.
Bem-vindo à CloudSec Academy, seu guia para navegar pela sopa de letrinhas dos acrônimos de segurança em nuvem e jargão do setor. Livre-se das distrações com conteúdo claro, conciso e habilmente elaborado, cobrindo os fundamentos para as melhores práticas.
Veja como a Wiz transforma fundamentos de segurança em nuvem em resultados reais.
IDOR (insecure direct object reference) is an access control flaw that leaks data when apps skip authorization checks. See how IDOR works and how to prevent it.
AI tokenomics, short for “token economics,” is the study and management of how large language models (LLMs) and other generative AI systems produce, price, and consume tokens.
A penetration testing (or pen test) methodology is a structured, repeatable framework that governs how ethical hackers plan, execute, document, and report a pen testing engagement.
API protection is how you discover, harden, and monitor APIs so attackers cannot abuse application logic or data. Learn risks, controls, and practices.
Veja como a Wiz transforma a visibilidade instantânea em uma remediação rápida.
A cloud access security broker (CASB) functions as a central policy enforcement point positioned between users and cloud-based applications.
Broken access control lets users exceed their permissions and ranks as OWASP A01. Learn the types, real examples, and how to prevent it in code and cloud.
Kubernetes networking gives every pod a unique IP on a flat network so pods, services, and external traffic communicate without NAT. Learn how it works.
API gateways route, authenticate, and control traffic between clients and backend services. Learn how they work, their benefits, and their security limits.
API testing verifies that your APIs return the right data, perform well, and stay secure. Learn the types, tools, testing process, and key best practices.
Container escape is when an attacker breaks out of a container’s isolation to gain unauthorized access to the host system.
Os guardrails de IA (também chamados de guardrails LLM ou guardrails GenAI) são controles preventivos de segurança que restringem o comportamento de um sistema de IA dentro dos limites de políticas definidos.
External vulnerability scanning is a way to find weaknesses in your public-facing systems by testing them from outside your network. This means you see your environment the same way an attacker on the internet would see it.
Open-source software (OSS) software composition analysis (SCA) tools are specialized solutions designed to analyze an application's open-source components and dependencies.
A inteligência de código aberto (OSINT) é uma estrutura que envolve coletar, analisar e interpretar dados disponíveis publicamente para obter insights sobre ameaças cibernéticas, atividades adversárias e técnicas de ataque. O OSINT identifica informações aparentemente inócuas que, se analisadas com a mentalidade de um invasor, podem revelar brechas críticas na postura de segurança de uma empresa.
As ferramentas de análise de composição de software (SCA) indexam suas dependências de software para dar visibilidade sobre os pacotes que você está usando e quaisquer vulnerabilidades que eles contenham.
Application security testing (AST) is a set of processes designed to detect and address security gaps during the early phases of the software development lifecycle (SDLC). In other words, teams take steps in pre-production to identify and mitigate risks before applications are released into operational environments.
SecDevOps is essentially DevOps with an emphasis on moving security further left. DevOps involves both the development team and the operations team in one process to improve deployment performance and service customers faster.
Managed cloud security helps organizations scale protection across cloud environments by outsourcing key operations like detection, response, and compliance monitoring.
Descubra os principais problemas de segurança na nuvem que afetam as organizações atualmente. Saiba como lidar com riscos, ameaças e desafios de segurança na nuvem para proteger seu ambiente de nuvem.