Blog

The Onam blog

New findings, deep dives on cloud attacks, and product updates from the Onam team.

Buyer's GuideFeatured

Onam vs. Wiz vs. Orca vs. Prisma Cloud: how to actually evaluate a cloud security platform

Wiz, Orca Security, and Prisma Cloud dominate every CSPM shortlist. Here are the seven questions that actually separate platforms — with Onam's answers on the record, and a checklist to run against every vendor on your list.

Onam Security TeamJuly 20, 20269 min read
Buyer's Guide
CDR

Beyond GuardDuty: how three-tier behavioral detection catches what rules miss

Rule-based detection catches known attack signatures. Statistical behavioral baselines catch incremental privilege escalation. ML anomaly detection catches the rest. Here's why you need all three.

Onam Security TeamJuly 15, 202610 min
CSPM

The 5 AWS misconfigurations we find in 90% of first scans

After thousands of first-time AWS scans, the same five misconfigurations show up in nearly every environment. Here's what they are — and how to fix them fast.

The Onam Security TeamJuly 10, 20266 min
Identity

CIEM vs IAM Security: what's actually the difference?

They sound identical. They aren't. Here's the practical split between IAM Security and Cloud Infrastructure Entitlement Management — and why you need both.

The Onam Security TeamJuly 3, 20265 min
Engineering

AI-powered cloud remediation: from finding to fix in minutes

The average MTTR for cloud security findings is 47 days. AI-powered remediation — context-aware code fixes, Ansible playbooks for CVEs, and threat narratives — is how we close that gap.

Onam Security TeamJune 30, 20268 min
Attack Path

Attack paths vs. misconfigurations: why toxic combinations are your real cloud risk

Most CSPM tools surface hundreds of misconfigurations. The ones that actually lead to breaches are the ones that chain together — and most tools can't show you which chains are dangerous.

The Onam Security TeamJune 24, 202611 min
Risk

The FAIR model for cloud security: putting a dollar value on your attack surface

CVSS scores rank vulnerability severity. FAIR answers the question your board actually cares about: what does this attack surface cost if it's breached? Here's how we apply it at Onam.

The Onam Security TeamJune 17, 20269 min
Containers

Kubernetes RBAC pitfalls that grant cluster-admin by accident

A ClusterRoleBinding here, an aggregated role there — and suddenly your read-only role can create pods that mount the host filesystem. Six patterns to audit today.

The Onam Security TeamJune 10, 20266 min
Vulnerability

EPSS over CVSS: prioritising the CVEs attackers actually exploit

CVSS tells you how bad a vulnerability could be. EPSS tells you how likely it is to be exploited in the next 30 days. Guess which one predicts breaches.

The Onam Security TeamJune 3, 20265 min
Identity

Why 90% of cloud IAM permissions are never used — and why that matters

Your IAM policies are accumulating unused permissions faster than your team can audit them. Here's what the data shows and how to close the gap.

Onam Security TeamMay 28, 20268 min
Threat Detection

MITRE ATT&CK for Cloud: mapping real attacks to your posture score

How MITRE ATT&CK for Cloud translates abstract threat techniques into concrete cloud misconfigurations — and how your posture score tracks each one.

Onam Security TeamMay 20, 202610 min
Engineering

How we check thousands of rules without agents: the architecture behind Onam

A technical deep-dive into how Onam scans dozens of cloud services across 7 clouds using only read-only access — no agents, no network changes, no configuration drift.

Onam Security TeamMay 6, 202610 min