<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PanIAM&apos;s Blog</title><description>Engineering notes, AWS security insights, and IAM deep dives from the team building PanIAM.</description><link>https://blog.paniam.cloud/</link><language>en-us</language><item><title>Project Glasswing and the CVE Avalanche: Why Your Cloud Blast Radius Is the New Control Plane</title><link>https://blog.paniam.cloud/posts/glasswing-cve-avalanche/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/glasswing-cve-avalanche/</guid><description>Anthropic&apos;s Glasswing signals either a wave of public CVEs or a wave of silent zero-days. Either way, exploitation now outruns patching, and cloud blast-radius visibility is the control that still works.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>cloud security</category><category>vulnerabilities</category><category>ai security</category><category>zero trust</category><author>Jean-Yves PASQUIER</author></item><item><title>The Blueprint Inspector: How PanIAM Secures Your Cloud Without Touching Your Data</title><link>https://blog.paniam.cloud/posts/external-id/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/external-id/</guid><description>Over-permissioned SaaS tools are a real risk. Here&apos;s how PanIAM accesses only the configuration it needs, and how you stay in control the entire time.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>security</category><category>cloud security</category><category>trust</category><author>Arthur WEBER</author></item><item><title>Google API Keys Are Now Secrets: How Gemini Changed the Rules</title><link>https://blog.paniam.cloud/posts/google-api-keys-are-now-secrets/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/google-api-keys-are-now-secrets/</guid><description>Google API keys were never treated as secrets — until Gemini made them dangerous. Learn how a leaked key can lead to massive bills and illegal AI usage.</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate><category>cloud security</category><category>secret detection</category><category>google cloud</category><author>Jean-Yves PASQUIER</author></item><item><title>The Hidden Path: Lateral Movement Through IAM Trust Policy Modification</title><link>https://blog.paniam.cloud/posts/lateral-movement-trust-policy/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/lateral-movement-trust-policy/</guid><description>How attackers leverage UpdateAssumeRolePolicy to move laterally across AWS environments, and why traditional permission analysis often misses this vector.</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate><category>lateral movement</category><category>aws security</category><category>iam</category><author>Jean-Yves PASQUIER</author></item><item><title>What Cybersecurity Leaders Will Do Differently in 2026</title><link>https://blog.paniam.cloud/posts/do-differently-2026/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/do-differently-2026/</guid><description>Cyber threats, cloud complexity, and regulation are reshaping cybersecurity. Here’s what leaders need to rethink in 2026 to stay resilient.</description><pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate><category>trends</category><category>risk management</category><author>Gil KATZ</author></item><item><title>Introducing Remediations: Unified Risk Prioritization for Cloud Security</title><link>https://blog.paniam.cloud/posts/vuln-remediations/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/vuln-remediations/</guid><description>PanIAM now analyzes both IAM policy misconfigurations and software vulnerabilities, using real-world exploit data to help security leaders prioritize fixes by actual risk reduction.</description><pubDate>Mon, 24 Nov 2025 00:00:00 GMT</pubDate><category>feature</category><author>Jean-Yves PASQUIER</author></item><item><title>NIS2: From Compliance to Competitive Advantage</title><link>https://blog.paniam.cloud/posts/nis2/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/nis2/</guid><description>Understanding NIS2, supply-chain accountability, and why proving security matters as much as having it</description><pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate><category>regulation</category><category>cloud security</category><category>Europe</category><author>Gil KATZ</author></item><item><title>Introducing Side Panels: Navigate Cloud Permissions in Seconds</title><link>https://blog.paniam.cloud/posts/side-panel/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/side-panel/</guid><description>Side Panels bring cloud permission details and escalation path intelligence directly into your PanIAM workflow. What took 10 minutes in your cloud console now takes 10 seconds.</description><pubDate>Thu, 16 Oct 2025 00:00:00 GMT</pubDate><category>feature</category><author>Arthur WEBER</author></item><item><title>Myth: We Have Backups and Can Just Pay the Ransom — So Ransomware Isn&apos;t a Big Threat</title><link>https://blog.paniam.cloud/posts/i_can_pay_the_ransom/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/i_can_pay_the_ransom/</guid><description>Myth about ransomware and backups.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>myths</category><category>cloud security</category><category>ransomware</category><author>Jean-Yves PASQUIER</author></item><item><title>Introducing Secret Detection: A New Layer of Security in Your IAM &amp; Network Graphs</title><link>https://blog.paniam.cloud/posts/introducing-secret-detection/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/introducing-secret-detection/</guid><description>Description of a new feature in Paniam that allows secrets to be monitored as resources or used for elevation of privileges.</description><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><category>feature</category><author>Jean-Yves PASQUIER</author></item><item><title>The EU&apos;s Cyber Resilience Act: Prepare your business</title><link>https://blog.paniam.cloud/posts/cyber-resilience-act/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/cyber-resilience-act/</guid><description>Explaining the EU&apos;s Cyber Resilience Act and showing how PanIAM can help businesses prepare</description><pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate><category>regulation</category><category>cloud security</category><category>Europe</category><author>Gil KATZ</author></item><item><title>Debunking the Myths: Cloud Providers Have My Back</title><link>https://blog.paniam.cloud/posts/cloud-has-my-back/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/cloud-has-my-back/</guid><description>Exploring the myth that cloud providers ensure complete data security and availability.</description><pubDate>Mon, 04 Aug 2025 00:00:00 GMT</pubDate><category>myths</category><category>cloud security</category><category>ransomware</category><author>Jean-Yves PASQUIER</author></item><item><title>Debunking the Myths: Why SMBs are Prime Targets in the Ransomware Age</title><link>https://blog.paniam.cloud/posts/why-smbs-are-prime-targets-in-the-ransomware-age/</link><guid isPermaLink="true">https://blog.paniam.cloud/posts/why-smbs-are-prime-targets-in-the-ransomware-age/</guid><description>Exploring the specialized ransomware ecosystem and why SMBs are prime targets. Learn how to protect your business.</description><pubDate>Wed, 09 Jul 2025 00:00:00 GMT</pubDate><category>SMBs</category><category>myths</category><category>ransomware</category><author>Jean-Yves PASQUIER</author></item></channel></rss>