Home / Companies / Prowler / Blog / September 2025

September 2025 Summaries

3 posts from Prowler

Filter
Month: Year:
Post Summaries Back to Blog
Prowler encourages community involvement during Hacktoberfest 2025 by inviting contributions to its open-source cloud security project. The company emphasizes the importance of transparency in security and offers various opportunities for participation, including fixing bugs, enhancing documentation, and developing new features. Prowler provides resources such as a comprehensive Developer Guide and a YouTube channel to assist contributors, as well as a Community Slack channel for support. The organization is also exploring the use of AI to facilitate contributions, with plans to introduce AI-powered coding agents. Contributors are encouraged to register for Hacktoberfest and can find inspiration from Prowler's public roadmap and a curated list of good first issues. The goal is to collaboratively build robust security tools, with Prowler highlighting the impact of both small and large contributions in securing cloud environments.
Sep 29, 2025 822 words in the original blog post.
Prowler has introduced a GitHub provider to enhance the security of software development pipelines by addressing vulnerabilities in repositories and organization settings. This initiative comes amid a rise in supply chain attacks, highlighting the need for robust security measures in both open source and private repositories. Prowler's new tool offers 17 checks aligned with the CIS GitHub Benchmark, revealing that default GitHub settings prioritize usability over security, as critical controls like branch protection and multi-factor authentication are not enabled by default. By using Prowler, organizations can identify and address security gaps quickly, leveraging tools like Lighthouse AI for actionable recommendations. Prowler Cloud provides continuous security assessments across various platforms, including GitHub, AWS, Azure, and Kubernetes, aiming to prevent vulnerabilities before they lead to supply chain attacks.
Sep 11, 2025 1,002 words in the original blog post.
Prowler has developed a Bulk Provider Provisioning tool to address the challenges of managing cloud security across multiple providers, such as AWS, Azure, and GCP, especially following organizational changes like mergers. This Python-based utility automates the onboarding process by reading provider configurations from a YAML file and provisioning them in Prowler Cloud or a self-hosted instance. The tool supports concurrent processing across multiple cloud environments, includes built-in connection testing, and allows for quick provisioning of numerous accounts, thus reducing the time and potential for errors associated with manual configuration. Additionally, Prowler offers continuous monitoring, real-time alerts, compliance reporting, and advanced analytics to enhance security operations. The Bulk Provider Provisioning tool is part of a broader suite of features in Prowler Cloud designed to simplify and scale cloud security management.
Sep 05, 2025 1,193 words in the original blog post.