2026-07-19
- A Well-Architected lens for Google Cloud: Plerion now maps your Google Cloud posture to the Google Cloud Well-Architected Framework. Review your workloads against Google’s own recommendations across all six pillars — operational excellence, security, reliability, cost optimization, performance, and sustainability — with answers populated from your Plerion findings. Learn more →
2026-07-18
- GCP coverage leaps forward, now with AI Security Posture Management: Plerion now discovers and continuously assesses 32 new GCP resource types, extending deep coverage across AlloyDB, Cloud Run, GKE, Spanner, Cloud Functions, Cloud Composer, Filestore, Datastream, Dataflow, Cloud Workstations, Secret Manager, Cloud TPU, and Batch, and most notably across Google’s AI stack: Vertex AI, Model Armor, and Document AI. Behind them ship 38 new posture checks (with 3 existing checks promoted to continuous runtime scanning), hardening everything from public data-plane exposure to encryption and network isolation.
- AI-SPM for the GenAI era: Fourteen of the new checks are purpose-built AI security posture management. Seven verify your Model Armor LLM guardrails are switched on and enforcing: prompt-injection and jailbreak defenses, malicious-URI blocking, sensitive-data (DLP) filtering, and Responsible-AI controls, so a misconfigured guardrail can’t quietly leave your models exposed. Six more lock down Vertex AI endpoints, Feature Stores, and Workbench instances for private networking and customer-managed encryption. And for the highest-risk exposures (a public GKE control plane, a public AlloyDB instance, or an anonymously invocable Cloud Run service), Plerion now goes beyond configuration and actively fact-checks them: it probes the live endpoint to confirm the exposure is genuinely reachable from the internet before it reaches your queue, so your most urgent findings arrive already verified.
2026-07-13
- Secure your AI agents on Amazon Bedrock AgentCore: Plerion now inventories your full AgentCore estate — gateways, runtimes, memory, and the MCP servers and tools your agents reach through them — and checks it against a new set of detections, so you can confirm every agent is configured properly and securely. It flags public invoke access, weak authorizers, non-enforcing policies, and insecure endpoints before an agent or one of its tools becomes an entry point.
2026-07-03
- Know which findings are running out of time: Failed findings now show an SLA status (within SLA, nearing breach, or breached) with the time left until their resolution deadline. Filter the findings dashboard by SLA status to focus on what’s closest to breaching. Learn more →
2026-07-01
- Refreshed MITRE ATT&CK Cloud coverage: Plerion updated its MITRE ATT&CK Cloud Matrix to Enterprise ATT&CK v19.1. Your threat mapping now reflects the current cloud technique set, including the Stealth and Defense Impairment tactics.
2026-06-27
- A new MITRE threat matrix: Plerion’s threat mapping now includes the MITRE ATT&CK Containers Matrix. See which adversary techniques your cloud and code posture covers across your container workloads.
2026-06-26
- A Well-Architected lens for financial services: Plerion now maps your AWS posture to the AWS Well-Architected Framework Financial Services Industry Lens. Review your workloads against the lens’s best practices for operational resilience, security, and reliability, with answers populated from your Plerion findings. Learn more →
2026-06-22
- Track your posture against Korea’s ISMS-P: Plerion now maps your cloud and code posture to ISMS-P, Korea’s integrated information security and personal information protection management certification. Turn it on from your compliance settings to track your posture control by control. Learn more →
2026-06-19
- Well-Architected reviews for your AI and ML workloads: Plerion now maps your AWS posture to two new AWS Well-Architected lenses: the Generative AI Lens and the Machine Learning Lens. Review your generative-AI and machine-learning workloads against each lens’s best practices, with answers populated from your Plerion findings. Learn more →
2026-06-18
- CWPP scanning, fully managed by Plerion: Scan your workloads without running any scanning infrastructure in your own account. Plerion hosts the appliances in its own accounts and scans across every supported CWPP region. Select it when you onboard an AWS account, and you’re done. Learn more in the platform docs →
2026-06-16
- Refreshed LGPD compliance coverage: Plerion re-mapped the Brazilian General Data Protection Law (LGPD) against today’s detection catalog, broadening coverage from two to nine of its data-protection articles and adding Kubernetes checks alongside AWS, Azure, and GCP. Your LGPD posture now reflects Plerion’s current cloud and code detections. Learn more →
2026-06-14
- Measure your AI systems against four security frameworks: Plerion now maps your cloud and code posture to ISO/IEC 42001, NIST AI Risk Management Framework (NIST AI RMF 1.0), OWASP Top 10 for LLM Applications (2025), and OWASP Top 10 for Agentic Applications (2026). Turn any of them on from your compliance settings to track your posture control by control. Learn more →
2026-06-03
- Trace any cloud asset back to the code that created it: Code to Cloud connects your GitHub repositories to the AWS assets they manage — so when a security finding fires, you know exactly where to go to fix it. On any asset’s detail page, you’ll see the responsible repository with a direct link. Flip it around in Code Security: open any repository and the new Assets tab shows every AWS asset it manages, giving you a clear picture of what’s at stake before making a change. On by default for all GitHub integrations. Supports CloudFormation, CDK, and Terraform. And when you ask Pleri to help remediate a finding, she’ll factor in the linked repository — giving you the right context to know where the fix belongs.
2026-05-04
- Exempted findings now stay out of your dashboard counts: Dashboard cards and their slide-over panels now respect exemptions — public assets, assets with critical or exploited vulnerabilities, overly permissive privileges, admin privileges, privilege escalation, attack paths, and failed findings all exclude anything you’ve marked as exempt. What you see is what actually needs attention.
2026-04-29
- Spot privilege escalation in your IAM policies: A new check, [PLERION-AWS-1013], identifies IAM roles, users, groups, and managed policies that allow actions that lead to privilege escalation. The contextual view breaks the offending permissions down — the escalation technique used, what permissions it escalates to, and which actions are required for the attack to succeed vs those that make it easier for an attacker. A new policy tab highlights the offending lines in each policy.
2026-04-13
- Plerion check updates: We’ve uplifted nine existing checks covering public exposure and access control across EC2, Application Load Balancers, Network Load Balancers, IAM, API Gateway V2, FPGA images, MediaStore, SES, and CloudWatch Logs, making findings clearer and more reliable.
- [PLERION-AWS-194] Ensure EC2 instances are not publicly accessible
- [PLERION-AWS-530] Ensure Amazon API Gateway V2 routes are authenticated
- [PLERION-AWS-553] Ensure IAM roles are not publicly accessible
- [PLERION-AWS-567] Ensure CloudWatch log resource policies are not publicly accessible
- [PLERION-AWS-568] FPGA Image (AFI) is publicly accessible
- [PLERION-AWS-571] Application Load Balancer (ALB) is publicly accessible
- [PLERION-AWS-575] Elemental MediaStore container is publicly accessible
- [PLERION-AWS-576] SES identity is publicly accessible
- [PLERION-AWS-862] Network Load Balancer (NLB) is publicly accessible
2026-03-26
- Let there be (less) light ☀️🌙: You can now toggle between Dark and Light mode straight from your profile menu. Go full night owl for those late-night incident reviews, or keep it bright for your 9am standups. Your retinas, your call.
2026-03-16
- Plerion check updates: We’ve improved five existing checks covering public exposure across SQS, Secrets Manager, S3 Glacier, Glue, and RDS, making findings clearer and more reliable.
- [PLERION-AWS-92] SQS queue is publicly accessible
- [PLERION-AWS-94] Secrets Manager secret is publicly accessible
- [PLERION-AWS-114] S3 Glacier vault is publicly accessible
- [PLERION-AWS-573] Glue data catalog is publicly accessible
- [PLERION-AWS-307] RDS DB cluster snapshot is publicly accessible
2026-03-05
- Say hello to new more AI-SPM checks: We’ve shipped 86 new checks across Amazon SageMaker and Amazon Bedrock, covering encryption, IAM privileges, network exposure, and runtime configuration.
View all 86 checks
View all 86 checks
- [PLERION-AWS-919] SageMaker AutoML job is encrypted with AWS-owned key
- [PLERION-AWS-920] SageMaker feature group is encrypted with AWS-owned key
- [PLERION-AWS-921] SageMaker model card is encrypted with AWS-owned key
- [PLERION-AWS-922] SageMaker domain is encrypted with AWS-owned key
- [PLERION-AWS-923] SageMaker training job is encrypted with AWS-owned key
- [PLERION-AWS-924] SageMaker transform job is encrypted with AWS-owned key
- [PLERION-AWS-925] SageMaker processing job is encrypted with AWS-owned key
- [PLERION-AWS-926] SageMaker hyperparameter tuning job is encrypted with AWS-owned key
- [PLERION-AWS-927] SageMaker compilation job is encrypted with AWS-owned key
- [PLERION-AWS-928] SageMaker data quality job definition is encrypted with AWS-owned key
- [PLERION-AWS-931] SageMaker endpoint config is encrypted with AWS-owned key
- [PLERION-AWS-932] SageMaker flow definition is encrypted with AWS-owned key
- [PLERION-AWS-933] SageMaker geospatial earth observation job is encrypted with AWS-owned key
- [PLERION-AWS-934] SageMaker geospatial vector enrichment job is encrypted with AWS-owned key
- [PLERION-AWS-935] SageMaker inference experiment is encrypted with AWS-owned key
- [PLERION-AWS-936] SageMaker inference recommendations job is encrypted with AWS-owned key
- [PLERION-AWS-937] SageMaker labeling job is encrypted with AWS-owned key
- [PLERION-AWS-938] SageMaker model bias job definition is encrypted with AWS-owned key
- [PLERION-AWS-939] SageMaker explainability job definition is encrypted with AWS-owned key
- [PLERION-AWS-940] SageMaker model package is encrypted with AWS-owned key
- [PLERION-AWS-941] SageMaker model quality job definition is encrypted with AWS-owned key
- [PLERION-AWS-942] SageMaker monitoring schedule is encrypted with AWS-owned key
- [PLERION-AWS-943] SageMaker notebook instance is encrypted with AWS-owned key
- [PLERION-AWS-944] SageMaker optimization job is encrypted with AWS-owned key
- [PLERION-AWS-946] SageMaker user profile is encrypted with AWS-owned key
- [PLERION-AWS-947] Bedrock automated reasoning policy is encrypted with AWS-owned key
- [PLERION-AWS-948] Bedrock data source is encrypted with AWS-owned key
- [PLERION-AWS-949] Bedrock evaluation job is encrypted with AWS-owned key
- [PLERION-AWS-950] Bedrock flow is encrypted with AWS-owned key
- [PLERION-AWS-951] Bedrock imported model is encrypted with AWS-owned key
- [PLERION-AWS-952] Bedrock model copy job is encrypted with AWS-owned key
- [PLERION-AWS-953] Bedrock model customization job is encrypted with AWS-owned key
- [PLERION-AWS-954] Bedrock model import job is encrypted with AWS-owned key
- [PLERION-AWS-955] Bedrock prompt is encrypted with AWS-owned key
- [PLERION-AWS-956] Bedrock session is encrypted with AWS-owned key
- [PLERION-AWS-957] SageMaker algorithm has admin privileges
- [PLERION-AWS-958] SageMaker AutoML job has admin privileges
- [PLERION-AWS-959] SageMaker cluster has admin privileges
- [PLERION-AWS-960] SageMaker domain has admin privileges
- [PLERION-AWS-961] SageMaker earth observation job has admin privileges
- [PLERION-AWS-962] SageMaker endpoint config has admin privileges
- [PLERION-AWS-963] SageMaker hyperparameter tuning job has admin privileges
- [PLERION-AWS-964] SageMaker image has admin privileges
- [PLERION-AWS-965] SageMaker MLflow tracking server has admin privileges
- [PLERION-AWS-966] SageMaker model has admin privileges
- [PLERION-AWS-967] SageMaker model package has admin privileges
- [PLERION-AWS-968] SageMaker notebook instance has admin privileges
- [PLERION-AWS-969] SageMaker pipeline has admin privileges
- [PLERION-AWS-970] SageMaker processing job has admin privileges
- [PLERION-AWS-971] SageMaker training job has admin privileges
- [PLERION-AWS-972] SageMaker user profile has admin privileges
- [PLERION-AWS-973] SageMaker vector enrichment job has admin privileges
- [PLERION-AWS-974] SageMaker notebook domain allows egress internet access to bypass VPC
- [PLERION-AWS-975] SageMaker AutoML job has overly permissive privileges
- [PLERION-AWS-976] SageMaker earth observation job has overly permissive privileges
- [PLERION-AWS-977] SageMaker hyperparameter tuning job has overly permissive privileges
- [PLERION-AWS-978] SageMaker processing job has overly permissive privileges
- [PLERION-AWS-979] SageMaker training job has overly permissive privileges
- [PLERION-AWS-980] SageMaker vector enrichment job has overly permissive privileges
- [PLERION-AWS-981] SageMaker cluster has overly permissive privileges
- [PLERION-AWS-982] SageMaker domain has overly permissive privileges
- [PLERION-AWS-983] SageMaker endpoint config has overly permissive privileges
- [PLERION-AWS-984] SageMaker algorithm has overly permissive privileges
- [PLERION-AWS-985] SageMaker image has overly permissive privileges
- [PLERION-AWS-986] SageMaker MLflow tracking server has overly permissive privileges
- [PLERION-AWS-987] SageMaker model has overly permissive privileges
- [PLERION-AWS-988] SageMaker model package has overly permissive privileges
- [PLERION-AWS-989] SageMaker notebook instance has overly permissive privileges
- [PLERION-AWS-991] SageMaker pipeline has overly permissive privileges
- [PLERION-AWS-992] SageMaker user profile has overly permissive privileges
- [PLERION-AWS-993] SageMaker notebook instance has root access enabled
- [PLERION-AWS-994] SageMaker notebook instance allows egress internet access to bypass VPC
- [PLERION-AWS-995] SageMaker endpoint without data capture enabled
- [PLERION-AWS-996] SageMaker pipeline allows privilege escalation
- [PLERION-AWS-997] SageMaker algorithm allows privilege escalation
- [PLERION-AWS-998] SageMaker AutoML job allows privilege escalation
- [PLERION-AWS-999] SageMaker cluster allows privilege escalation
- [PLERION-AWS-1000] SageMaker domain allows privilege escalation
- [PLERION-AWS-1001] SageMaker earth observation job allows privilege escalation
- [PLERION-AWS-1002] SageMaker endpoint config allows privilege escalation
- [PLERION-AWS-1003] SageMaker hyperparameter tuning job allows privilege escalation
- [PLERION-AWS-1004] SageMaker image allows privilege escalation
- [PLERION-AWS-1009] SageMaker processing job allows privilege escalation
- [PLERION-AWS-1010] SageMaker training job allows privilege escalation
- [PLERION-AWS-1011] SageMaker user profile allows privilege escalation
- [PLERION-AWS-1012] SageMaker vector enrichment job allows privilege escalation
2026-03-03
- CloudFormation updates, minus the manual effort: Auto stack update keeps your Plerion stack current with secure, controlled rollouts. Review changelogs, skip versions if needed, and rely on cryptographic verification and isolated execution for peace of mind. Learn more in the platform docs →
2026-02-04
- Plerion check updates: This release includes a second round of improvements to existing Plerion checks, making findings clearer and more reliable. The following checks were improved:
- [PLERION-AWS-78] Redshift cluster does not have encryption in transit enforced
- [PLERION-AWS-89] SNS topic is publicly accessible
- [PLERION-AWS-102] Lambda layer is publicly accessible
- [PLERION-AWS-103] Serverless Application Repository application is publicly accessible
- [PLERION-AWS-122] MSK cluster does not have encryption in transit enforced for broker-to-broker traffic
- [PLERION-AWS-123] MSK cluster does not have encryption in transit enforced for client-to-broker traffic
- [PLERION-AWS-131] MemoryDB cluster does not have encryption in transit enabled
- [PLERION-AWS-138] SageMaker endpoint does not have a KMS key configured for volume encryption
- [PLERION-AWS-166] ElastiCache for Redis cluster does not have encryption in transit enabled
- [PLERION-AWS-180] DocumentDB cluster parameter group does not have encryption in transit enforced
- [PLERION-AWS-572] EventBridge event bus is publicly accessible
- [PLERION-AWS-824] RDS cluster does not have encryption in transit enforced
- [PLERION-AWS-825] RDS instance does not have encryption in transit enforced
- [PLERION-AWS-844] EFS file system enforces encryption in transit
- [PLERION-AWS-128] Ensure Amazon Neptune cluster parameter groups use SSL connections so that they have encryption in transit enabled
- [PLERION-AWS-840] Ensure Amazon S3 Glacier vaults are encrypted at rest
- [PLERION-AWS-841] Ensure Amazon S3 Glacier vaults have encryption in transit enabled
- [PLERION-AWS-845] Ensure Amazon DynamoDB tables have encryption in transit enabled
- [PLERION-AWS-846] Ensure Amazon EC2 AMIs have encryption in transit enabled
- [PLERION-AWS-847] Ensure Amazon Elastic Block Store (EBS) volumes have encryption in transit enabled
- [PLERION-AWS-848] Ensure Amazon Elastic Block Store (EBS) snapshots have encryption in transit enabled
- [PLERION-AWS-853] Ensure AWS Glue data catalogs have encryption in transit enabled
- [PLERION-AWS-856] Ensure Amazon DynamoDB tables are encrypted at rest
2026-02-02
- Environment wrangling, simplified: Manage Production and Non-production classifications for every cloud integration from one place.
Open the Environments page →
2026-01-13
- New year, newly improved checks: We’re starting the year strong with a round of improvements to existing Plerion checks, helping you identify misconfigurations more clearly and keep your cloud environments secure. Here is the first batch of improved checks, with clearer and more consistent language:
- [PLERION-AWS-149] EMR cluster does not have encryption in transit enabled
- [PLERION-AWS-157] OpenSearch domain does not enforce HTTPS
- [PLERION-AWS-229] CloudFront distribution does not enforce HTTPS for viewers and origins
2025-12-11
- Meet your new workload scanning metronome: Define how often your workloads are scanned with daily, recommended or custom schedules. More control and clearer coverage, your way.
2025-11-28
- Go global with the new global filter: Set your context across the platform using top-level filters on environment, asset group or integration. More improvements coming soon!
2025-11-24
- Environment classification has arrived: Bring order to your cloud universe by classifying your integrations as Production or Non-production. Zoom into the environment you care about and understand issues with sharper context.
2025-10-08
- Attack paths for Azure environments: Azure joins the lineup! You can now explore how risks link across your environment and see exactly where to focus your fixes.
View the attack paths in action!
View the attack paths in action!