In August 2026, U.S. healthcare technology company CareCloud formally reported a data breach to the U.S. Department of Health and Human Services (HHS), confirming that personal information belonging to as many as 3,756,469 patients had been stolen following a March 2026 intrusion into its AWS cloud environment. The compromised information included Social Security numbers (SSNs), medical records, and payment card information.
This figure was more than ten times the approximately 345,000 individuals initially reported, making it the fifth-largest healthcare data breach of 2026 to date. Beyond raising serious concerns about data security in the healthcare sector, the incident has prompted enterprises worldwide to reassess the urgency of protecting cloud workloads. Against this backdrop, AIStorm CloudGuard provides enterprises with a full-stack cloud workload security solution spanning asset discovery, vulnerability management, and threat protection.
CareCloud provides electronic health records (EHR), revenue cycle management, and practice management software to more than 45,000 healthcare providers across the United States. By compromising its AWS environment, attackers effectively gained access to a gateway containing data connected to tens of thousands of healthcare organisations.
The incident highlights a critical issue—not simply the failure of traditional perimeter security, but security blind spots at the cloud workload layer. As enterprises migrate critical business systems to the cloud, they may assume that the cloud service provider is responsible for security, while overlooking their own responsibility for protecting workloads running within the cloud.
Key Blind Spots in Cloud Workload Security
Cloud workload security challenges typically arise in several key areas.
Incomplete visibility of cloud assets. In multi-cloud and hybrid-cloud environments, enterprises often struggle to maintain a real-time inventory of all cloud hosts, containers, and serverless instances. Shadow assets and unmanaged workloads can therefore become attractive entry points for attackers.
Prolonged vulnerability exposure. Remediating vulnerabilities in cloud environments often requires system restarts and formal change approvals. The period between vulnerability disclosure and patch deployment can extend for weeks or even months, leaving attackers with significant opportunities for exploitation.
Inconsistent security policies across hybrid-cloud environments. Security policies across heterogeneous environments such as VMware, OpenStack, and KVM are often managed independently, making unified management and coordinated protection difficult.
Ransomware and cloud misconfigurations. Misconfigured cloud storage buckets and excessive access privileges have become major contributors to large-scale data breaches, while ransomware increasingly targets cloud workloads directly for encryption.
One CWPP. Every Cloud.
Faced with these systemic challenges, enterprises need more than another isolated security tool. They need a platform capable of protecting cloud workloads throughout their entire lifecycle.
AIStorm CloudGuard is designed for this purpose. As a core product of AIStorm, the global brand of AsiaInfo Security, CloudGuard is built around the proposition “One CWPP. Every Cloud.”
CloudGuard provides comprehensive coverage across the major Cloud Workload Protection Platform (CWPP) workload protection models, delivering full-stack security capabilities from asset discovery and vulnerability management to threat protection. It enables enterprises to build a proactive, intelligent, and defence-in-depth security framework for their workloads.

Unified Asset Visibility and Vulnerability Management
AIStorm CloudGuard automatically discovers assets across physical hosts, virtual machines, containers, and serverless instances. Powered by more than 5,000 asset identification rules, it establishes a comprehensive asset topology that enables enterprises to identify at-risk assets and exposed attack surfaces within minutes.
For vulnerability management, CloudGuard incorporates more than 50,000 vulnerability rules, providing comprehensive vulnerability scanning and remediation prioritisation.
It also supports virtual patching technology, which protects vulnerabilities at the application traffic layer. This allows enterprises to block attacks targeting known vulnerabilities without restarting business systems, significantly reducing the vulnerability exposure window.
Unified Hybrid-Cloud Management
AIStorm CloudGuard enables unified management across heterogeneous environments including VMware, OpenStack, and KVM, helping organisations maintain consistent security policies and continuous management across hybrid-cloud environments.
This addresses one of the most persistent challenges in hybrid-cloud security: fragmented policies and disconnected security controls across different infrastructures.
Advanced Threat and Ransomware Protection
For threat protection, CloudGuard uses a multi-engine collaborative detection mechanism supporting more than 3,000 file formats, with coverage across over 20 ransomware families and 30 Trojan families.
It also provides dedicated ransomware protection through ransomware gene identification, decoy-file detection, and millisecond-level behavioural blocking—enabling malicious encryption activity to be stopped before ransomware can cause significant damage.
Lightweight, Integrated Agent Architecture
AIStorm CloudGuard adopts a lightweight, integrated Agent architecture. A single Agent combines comprehensive proactive defence capabilities, including firewall, intrusion prevention, file protection, and process protection.
Peak CPU utilisation can be kept below 5%, supported by an adaptive intelligent analysis mechanism that reduces resource consumption while maintaining detection effectiveness. This avoids the performance overhead and management complexity commonly associated with deploying multiple independent security Agents.
Proven Across Key Industries
AIStorm CloudGuard's capabilities have been validated across multiple critical industries.
In the financial sector, a regional bank deployed the solution to achieve comprehensive visibility of host assets and accurately identify attack surfaces and malicious activity. The deployment covered its headquarters, 35 branches, hundreds of subsidiaries, and more than 350,000 endpoints.
In the automotive manufacturing sector, a major automotive electronics company used the solution to establish closed-loop vulnerability lifecycle management and monitoring of unknown threats, covering its headquarters, branches, and all seven of its global R&D centres.
In the new energy sector, a major power-battery manufacturer used CloudGuard's virtual patching technology to protect internet-facing applications, reducing overall server resource consumption while improving business stability.
Cloud Security Is a Shared Responsibility
The CareCloud incident reinforces a fundamental reality: moving to the cloud does not eliminate an organisation's security responsibilities.
Under the shared responsibility model, cloud service providers are responsible for securing the underlying cloud infrastructure, while enterprises remain responsible for protecting their own workloads, applications, data, identities, and configurations within the cloud.
Cloud Workload Protection Platforms (CWPPs) are therefore becoming a foundational component of enterprise cloud security rather than an optional layer.
AIStorm CloudGuard provides one platform for every cloud, helping enterprises move away from fragmented security architectures built through continuously adding isolated tools toward an integrated model centred on discovery, prevention, and continuous monitoring.
As enterprises accelerate their intelligent and digital transformation, cloud workload security will increasingly become an integral part of digital strategy. AIStorm CloudGuard enables organisations to secure critical workloads across diverse cloud environments while supporting resilient and sustainable cloud operations.
At AIStorm, cyber resilience is not built through isolated security products. It is achieved through a continuous security cycle of visibility, protection, detection and improvement.
1.Find
The first step is knowing what is exposed.
Using External Attack Surface Management (EASM), organisations can continuously discover internet-facing assets, identify shadow IT, uncover forgotten services, and understand where external risks exist before attackers exploit them.
2.Block
Once exposure is identified, risks should be reduced as quickly as possible.
Virtual patching provides immediate protection for vulnerable and legacy systems without waiting for maintenance windows, software upgrades or application changes—helping organisations minimise risk while maintaining business continuity.
3.Monitor
Cyber threats evolve continuously.
Network Detection & Response (NDR), combined with Threat Intelligence, enables organisations to monitor network activity, detect suspicious behaviour, identify emerging threats, and uncover attacker activity before incidents escalate.
4.Remediate
Security does not end after detection.
The final step is closing the loop—prioritising remediation, reducing measurable risk, and continuously strengthening operational resilience as the threat landscape evolves.
This is an Exposure-to-Response approach: transforming cybersecurity from periodic assessments into a continuous security lifecycle.