September 22, 2026 · Remediation. The first thing we automated was restraint. Tamnoon is named as a Sample Vendor for Autonomous Exposure Remediation category in the 2026 Gartner® Emerging Tech Impact Radar: Preemptive Cybersecurity. (Full citation at the foot of this page) The word
September 14, 2026 · Remediation. For a decade, cloud security invested in finding problems faster. It worked. Detection is measured in minutes now, and nobody seriously argues it is the bottleneck anymore. A new Gartner research note, “Risk-Aware Operational Trust Will Drive Adoptio
August 13, 2026 · AI & agents. Two companies can run identical cloud security tools, receive identical findings, and still need completely different fixes. Cloud security tools are good at what they do.
August 3, 2026 · Identity & access. Voices in Cloud Security is a series of candid conversations with people who work in and around cloud security. This one is with Michael St. Onge.
July 29, 2026 · AI & agents. Cortex tells your agent what’s wrong. With Tamnoon MCP, it now also learns what matters, who owns it, and how to fix it safely. Security teams are moving past chat assistants and toward agents that act.
July 28, 2026 · Practice & operations. The first 180 days set the tone for everything that follows in a CISO role. Get them right, and you build the trust, the relationships, and the credibility that make the rest of the job possible.
July 27, 2026 · Practice & operations. A remediation plan is only as good as your ability to find who owns the fix. Does this sound familiar?
July 27, 2026 · CNAPP & posture. CNAPP is now the default cloud security category.
July 22, 2026 · Research & CTF. An AI agent was told to pass a test, so it broke out of its lab, hacked a production database, and took the answers.
July 7, 2026 · Remediation. 53% of CNAPP detections are still open, and the number is growing. Most organizations follow the same playbook after deploying a new security tool or CNAPP.
June 30, 2026 · CNAPP & posture. This is the first installment of Voices in Cloud Security, a series where we talk to cloud security practitioners across the industry about what they see in the field, what’s broken, and what needs to change.
June 29, 2026 · AI & agents. Every button in your enterprise software exists because a human had to click it. Enterprise software became complex for a simple reason. Humans needed to navigate complexity by hand.
June 23, 2026 · Company. Safely fixing cloud vulnerabilities requires understanding how they are exploited, but that kind of research runs into guardrails on most AI platforms. Legitimate defensive security work shares DNA with offensive techniques.
June 22, 2026 · CNAPP & posture. Cortex Cloud merged CNAPP and CDR into one platform, but the CNAPP remediation workflow for each still looks nothing alike.
June 16, 2026 · Remediation. Zero production incidents should be the benchmark for any company looking at automated cloud remediation. That also happens to be the track record Tami has across every cloud remediation it has executed to date.
June 15, 2026 · CNAPP & posture. Cortex Cloud surfaces risks across posture, identity, data, and runtime in a single platform. Closing those findings across thousands of resources safely at production scale is a different problem entirely.
June 9, 2026 · CNAPP & posture. Wiz built the detection and security platform that cloud teams trust. Tamnoon built the remediation for Wiz that turns trust into results.
June 1, 2026 · AI & agents. Tamnoon now integrates with Claude Security.
May 6, 2026 · Vulnerabilities. NIST announced recently that it’s overhauling National Vulnerability Database (NVD) operations to keep up with record CVE growth. The volume has outpaced their capacity to enrich every submission, so they’re changing the model.
April 24, 2026 · Research & CTF. Google Cloud Next 2026 made one thing clear: the cloud security industry is done pretending detection is enough.
April 13, 2026 · AI & agents. Anthropic just announced Claude Mythos Preview and Project Glasswing.
April 10, 2026 · Research & CTF. An engineer, a CRO, and a sales rep walk into RSAC. Sounds like the start of a joke, but the punchline is that everyone’s selling the same AI wrapper.
March 31, 2026 · Practice & operations. You walk out of every quarterly security review (QSR) with the same uneasy feeling: you just presented 45 minutes of charts, and you still can’t prove the organization is more secure than last quarter.
March 25, 2026 · Remediation. Forrester just killed endpoint security. Not the practice, but the entire category. After a decade of xWaves, evaluations, and vendor rankings, they retired the whole thing.
February 26, 2026 · Remediation. Nobody wants another cloud security tool. We heard that loud and clear after engaging with cloud security professionals across hundreds of conversations. But the same six themes did keep surfacing.
February 25, 2026 · Company. Our fiscal year just ended, but let’s recap what happened over the past year. When we started Tamnoon, the thesis was simple: the cloud security industry doesn’t have a detection problem. It has a remediation problem.
February 11, 2026 · Remediation. The AI trust paradox is simple: everyone wants to automate faster, but no one wants to be the one who breaks production. Until AI can prove it can fix safely, security debt keeps piling up.
January 13, 2026 · Remediation. Cloud security does not struggle because teams lack visibility, but because no one clearly owns what happens after risk is found.
November 26, 2025 · Research & CTF. Ever wonder what happens when a single secret ends up copy-pasted across dozens of cloud services? Or how fast that quiet mistake can turn into a wide-open blast radius?
November 20, 2025 · Remediation. The real risk in cloud security comes from the time between when an alert appears and when a fix is made. Alerts stack up by the thousands, each one waiting to be investigated, validated, and routed to the right person.
November 5, 2025 · Research & CTF. We’re back at it again with another Wiz Cloud Security Championship challenge. In our last write-up, “Contain Me If You Can,” we explored container escapes and database privilege abuse. This time, the walls look different.
October 27, 2025 · Research & CTF. Wiz’s Cloud Security Championship Challenge #2, You’re trapped inside a container and need to reach the host file system to find the flag.
October 8, 2025 · Research & CTF. Tamnoon’s security engineer breaks down AWS IMDS risks revealed in the Wiz Cloud Security Challenge.
October 6, 2025 · Practice & operations. MDR protects endpoints, not cloud workloads. Strengthen your cloud security with detection and response built for AWS, Azure, and GCP.
September 30, 2025 · Identity & access. Managing AWS root users has always been challenging. Every member account in an AWS organization comes with its own root credentials, and as accounts multiply, so does the complexity of enforcing strong controls like MFA.
August 28, 2025 · Company. After more than two decades helping some of the most innovative Israeli startups bring their ideas to the global stage, I’m excited to start my next chapter as Chief Revenue Officer at Tamnoon.
August 6, 2025 · Practice & operations. We get this question a lot: “Are we the right kind of company for a managed cloud security service?” And honestly, sometimes the answer is no. That’s not a red flag.
June 11, 2025 · Practice & operations. Security teams are drowning in metrics, and most of them don’t matter. The reality is simple: security teams don’t operate in a vacuum.
June 9, 2025 · CNAPP & posture. Cloud infrastructure doesn’t break the same way on-prem did. But it still breaks.
May 28, 2025 · CNAPP & posture. Cloud-native environments demand security approaches that evolve just as quickly as the infrastructure they protect.
May 14, 2025 · Remediation. Most organizations don’t have a detection problem, they have a remediation problem. Cloud security teams are flooded with alerts, yet few ever get resolved.