Prowler May 2026 Newsletter

This is a republishing of our monthly newsletter.
Hi everyone ๐
It's been a busy spring at Prowler HQ โ we've shipped a steady stream of improvements: a brand-new Alerts system, an official GitHub Action plus CI/CD pipeline scanning, a new Vercel provider, deeper coverage for GenAI and identity, a much faster triage experience, and a new compliance framework. And we're hitting the road this summer โ fwd:cloudsec, AWS Summit Madrid, and AWS Summit NYC. Come say hi!
Here's what's new in Prowler ๐
๐ Introducing Alerts
Stop checking the dashboard โ let Prowler tell you
Prowler now pushes critical findings straight to the people who need to know. Organization owners get an auto-provisioned daily digest of critical findings out of the box, and admins can build custom alert rules scoped by provider, account, severity, and status โ routed to specific users, with one-click unsubscribe. Detection only matters if someone acts on it, and Alerts close that loop.
๐ข New Provider: Vercel
Prowler now supports Vercel. Connect your Vercel teams with an API token and audit deployments, domains, projects, and team settings, with 26 security checks out of the box.
๐ Explore Vercel checks โ
โ๏ธ Official GitHub Action + CI/CD Pipeline Scanning
Prowler's GitHub Action is now officially published โ drop it into any workflow and findings flow straight into GitHub Code Scanning as SARIF, with an optional push to Prowler Cloud. Two more pieces complete the shift-left story:
- GitHub Actions workflow scanning, powered by zizmor, flags OWASP Top 10 CI/CD risks โ script injection, untrusted checkouts, and other supply-chain footguns โ before they ship.
- IaC scanning now emits SARIF, so Terraform, CloudFormation, and Kubernetes misconfigurations get annotated right on the pull request.
The cheapest misconfiguration to fix is the one that never gets merged โ this brings Prowler all the way into the developer's pull request.
๐ Get the GitHub Action โ
๐ค Securing the AI Stack: AWS Bedrock + Google Workspace
As teams wire GenAI into production, Prowler is keeping pace:
- AWS Bedrock hardening โ guardrails configured, prompt management in place, CMK encryption, no Bedrock full-access policies, stale IAM access to Bedrock flagged, and VPC endpoints enforced.
- Google Workspace (Gmail) โ new CIS-aligned checks covering attachment safety, spoofing and phishing protection, link safety, delegation, and access controls, via the Cloud Identity Policy API.
GenAI services and collaboration suites are part of your attack surface now โ and most teams have no guardrails on them. These give you a baseline on day one.
๐ Explore the checks on Prowler Hub โ
๐ Tighter Microsoft 365 Identity Coverage
Five new Entra Conditional Access checks โ policies covering all apps and users, MFA for guests, blocking unknown/unmanaged devices, sign-in frequency enforcement, and excluding the directory sync account โ plus new Intune device-compliance and Exchange mailbox resiliency checks. Identity is the perimeter now, and Conditional Access gaps are exactly where attackers walk in.
๐ New Compliance Framework: ASD Essential Eight (AWS)
The Australian Signals Directorate's Essential Eight Maturity Model is now a first-class framework for AWS โ map your AWS posture to Essential Eight maturity levels out of the box. It's a hard requirement for Australian government and a widely adopted baseline across APAC, so it's one more framework you don't have to build and maintain yourself.
๐ A Faster Path from Finding โ Fix
We rebuilt the parts of the product you spend the most time in:
- Finding detail drawer redesign โ remediation gets its own tab, the status verdict sits up top, resource context is front and center, and carousel navigation shows status instantly while the full record loads.
- Resources side drawer โ metadata, findings, and event timelines now live in one drawer, so you investigate without losing your place.
- Attack Paths polish โ finding details open inline over the graph (your zoom and filters stay put), with clearer scan selection.
- Compliance page redesign โ client-side framework search, streamlined scan selectors, cleaner cards, and downloadable CIS Benchmark PDFs for the latest variant of each provider.
Triage speed is the whole game. Every click we remove between spotting a problem and fixing it is time back for your team.
โจ Also worth a look
- Syntax highlighting on remediation code blocks, with provider-aware detection for Shell, HCL, YAML, and Bicep
- Exclude specific AWS regions via --excluded-region, environment variables, or config files
- Remediation links now point to authoritative sources (CVE.org, Prowler Hub, GitHub Security Advisories) instead of third-party mirrors
- ThreatScore pillars render in canonical order, are clickable, and always show in full
- Imported OCSF scans generate downloadable reports that match CLI scan outputs
๐ Try It Free on Prowler Cloud
๐ Meet Prowler at Upcoming Events
This summer we're at three events across the US and Europe โ come for a live demo, talk multi-cloud security, and grab some swag.
fwd:cloudsec North America 2026
June 1โ2, 2026 ยท Meydenbauer Center, Bellevue (Seattle area), WA
Prowler is a sponsor of the cloud security community's favorite gathering. Find the team there to talk attack paths, multi-cloud coverage, and what's next on the roadmap.
๐ Learn more โ
AWS Summit Madrid 2026 โ Booth B15
June 4, 2026 ยท IFEMA Madrid
Visit us at Booth B15 for live demos of Prowler Cloud and a look at how teams secure AWS โ and everything else โ from one place.
๐ Learn more โ
AWS Summit NYC 2026 โ Booth 453
June 17, 2026 ยท Javits Center, New York
Stop by Booth 453 to see Prowler in action โ including the new GitHub Action, Alerts, and GenAI coverage.
๐ Learn more โ
โก That's a Wrap
Thanks for being part of the growing Prowler community.
Stay secure โ and come find us this summer!
- The Prowler Team




.avif)

.avif)





