Upwind reveals ArgoCD XSS enabling Kubernetes cluster takeover
The vulnerability affects ArgoCD versions through 3.4.4; attackers can abuse administrator sessions and ArgoCD privileges to deploy malicious workloads, while no upstream patch exists.
See the latest news and media coverage for Upwind. We track all announcements, press releases, and industry mentions in real time, all in one place.
Last updated
In short: Upwind reached a $3.8 billion valuation, launched an AI-powered agentic security workforce, and appointed a new Chief Business Officer.
The vulnerability affects ArgoCD versions through 3.4.4; attackers can abuse administrator sessions and ArgoCD privileges to deploy malicious workloads, while no upstream patch exists.
The AI-powered beta tool autonomously investigates threats, correlating evidence to deliver verdicts with reasoning and confidence levels.
CVE-2026-72898 allows unauthenticated SQL injection in password reset endpoint, granting admin access and compromising connected production databases.
The worm steals credentials, spreads through npm and IDE hooks, and uses an Ethereum smart contract for command and control. Upwind detects it via runtime behavior.
Upwind Security, a startup offering cybersecurity for artificial intelligence and cloud applications, is raising fresh financing that values the company at $3.8 billion, according to...
New York, USA, August 4th, 2026, FinanceWireOpen-source software has long been built on trust. Developers routinely install...
Upwind, the runtime-first cloud security leader, today announced the launch of its AI Agentic Pack, a new set of specialized AI agents built into its...
Upwind Security is expanding in India after a $250 million funding round, focusing on runtime cloud protection, AI-driven cyber threats, and DPDP compliance.
Track Upwind and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Upwind and other trending companies.