TGViewer
Channel Public Channel
CloudSec Wine

CloudSec Wine

@cloud_sec

All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Subscribers
2.28K
Photos
1.1K
Videos
0
Links
1.4K

Showing posts older than #1003 · Back to latest

Older Posts 20 shown
Post #996 546
🔶 When AI Gets Hijacked: Exploiting Hosted Models for Dark Roleplaying

Permiso has found that some attackers are using hijacked LLM infrastructure to power highly inappropriate AI chatbot services.

https://permiso.io/blog/exploiting-hosted-models

#aws
  • 👍 3
  • ❤ 1
  • 🔥 1
Post #994 630
🔴 CloudImposer: Executing Code on Millions of Google Servers with a Single Malicious Package

Tenable Research discovered a remote code execution (RCE) vulnerability in GCP that could have allowed an attacker to hijack an internal software dependency that Google pre-installs on each Google Cloud Composer pipeline-orchestration tool.

https://www.tenable.com/blog/cloudimposer-executing-code-on-millions-of-google-servers-with-a-single-malicious-package

#gcp
  • 🔥 3
  • ❤ 1
  • 👍 1
Post #992 565
👩‍💻 Backdooring Azure Automation Account Packages and Runtime Environments

This article explores techniques for backdooring Azure Automation Account packages and runtime environments. It covers creating malicious packages, exploiting package dependencies, and manipulating runtime environments to gain persistent access and execute arbitrary code within Azure Automation Accounts.

https://www.netspi.com/blog/technical-blog/cloud-pentesting/backdooring-azure-automation-account-packages-and-runtime-environments/

#azure
  • 👍 3
  • ❤ 1
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →