TGViewer
Channel Public Channel
CloudSec Wine

CloudSec Wine

@cloud_sec

All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Subscribers
2.28K
Photos
1.1K
Videos
0
Links
1.4K

Showing posts older than #1026 · Back to latest

Older Posts 20 shown
Post #1023 549
🔶 EMERALDWHALE: 15k Cloud Credentials Stolen in Operation Targeting Exposed Git Config Files

This campaign used multiple private tools that abused multiple misconfigured web services, allowing attackers to steal credentials, clone private repositories, and extract cloud credentials from their source code. Credentials for over 10,000 private repositories were collected during the operation.

https://sysdig.com/blog/emeraldwhale/

(Use VPN to open from Russia)

#aws
  • 🔥 4
  • ❤ 1
  • 👍 1
Post #1022 740
🔶 Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy

The article explores how threat actors manage to work around the limitations of the quarantine policy (AWSCompromisedKeyQuarantineV2) that is applied to identities whose credentials are leaked.

https://permiso.io/blog/introducing-detention-dodger

#aws
  • 👍 2
  • ❤ 1
  • 🔥 1
Post #1019 587
🔶 How to use the Amazon Detective API to investigate GuardDuty security findings and enrich data in Security Hub

How to integrate Amazon Detective with AWS Security Hub, giving you better visibility into threat indicators and investigative data directly from Security Hub, which provides you with a centralized view of your overall security posture across your AWS accounts.

https://aws.amazon.com/ru/blogs/security/how-to-use-the-amazon-detective-api-to-investigate-guardduty-security-findings-and-enrich-data-in-security-hub/

(Use VPN to open from Russia)

#aws
  • 👍 2
  • ❤ 1
  • 🔥 1
Post #1015 510
🔶 AWS IAM Policy Condition Operators Explained

There are 27 basic condition operators you can use in an AWS IAM policy. Then you can add "ForAllValues" or "ForAnyValue" to the beginning and "IfExists" to the end of almost all of them.

https://iam.cloudcopilot.io/resources/operators

#aws
  • 👍 3
  • ❤ 1
  • 🔥 1
Post #1014 548
🔶 Security Logging in Cloud Environments - AWS

Author has refreshed article which covers how to design a state of the art multi-account security logging platform in AWS: removed stale links and legacy advice on MFA delete, added API Gateway access logs, and added a "Tracking Misconfigurations" section.

https://blog.marcolancini.it/2021/blog-security-logging-cloud-environments-aws/

#aws
  • 👍 5
  • ❤ 1
  • 🔥 1
Post #1010 579
🔶 Turning AWS Documentation into Gold: AI-Assisted Security Research

This article goes over how to use embeddings in AWS Bedrock, scraping AWS documentation, leveraging ripgrep for fast searches on local disk, and some interesting security research along the way.

https://www.securityrunners.io/post/ai-assisted-security-research

#aws
  • 👍 3
  • ❤ 1
  • 🔥 1
Post #1007 566
  • 👍 2
  • 🤯 2
  • ❤ 1
  • 🔥 1
Post #1003 557
🔶 AWS Launches Improvements for Key Quarantine Policy

AWS made improvements to the AWSCompromisedKeyQuarantine policies in order to protect potentially compromised accounts. The changes were based on threat intelligence gathered from attacks being seen in the wild.

https://sysdig.com/blog/aws-launches-improvements-for-key-quarantine-policy/

(Use VPN to open from Russia)

#aws
  • 👍 3
  • ❤ 1
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →