TGViewer
Channel Public Channel
CloudSec Wine

CloudSec Wine

@cloud_sec

All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Subscribers
2.27K
Photos
1.1K
Videos
0
Links
1.4K

Showing posts older than #1108 · Back to latest

Older Posts 20 shown
Post #1102 561
🔶 Abusing AWS Serverless Image Handler

The AWS solution "Dynamic Image Transformation for Amazon CloudFront", previously known as "AWS Serverless Image Handler", contains a configuration weakness where the role associated with the Lambda does not constrain which buckets can be accessed. The environment variable can be set to a wildcard allowing access to any bucket.

https://www.o3c.no/knowledge/abusing-aws-serverless-image-handler

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1101 546
🔶 The Cat Flap - How to really Purrsist in AWS Accounts

A playful guide to creating covert backdoors in AWS accounts, specifically using the AWSControlTowerExecution role.

https://rootcat.de/blog/thecatflap/

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1099 561
🔶 Announcing ASCP integration with Pod Identity: Enhanced security for secrets management in Amazon EKS

The integration of ASCP with Pod Identity marks a significant step forward in secrets management for Amazon EKS. It offers enhanced security, simplified configuration, and improved operations.

https://aws.amazon.com/ru/blogs/security/announcing-ascp-integration-with-pod-identity-enhanced-security-for-secrets-management-in-amazon-eks/

(Use VPN to open from Russia)

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1096 559
👩‍💻 What in the MFA? Deconflicting MFA settings in Microsoft Entra ID

Post discussing the challenges of managing multifactor authentication (MFA) settings in Microsoft Entra ID, especially in light of evolving threats.

https://www.securesloth.com/home/what-in-the-mfa

#azure
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1093 511
🔶 Implement effective data authorization mechanisms to secure your data used in generative AI applications - part 2

Depending on where the data sits as part of the generative AI application, you will need to use different implementations of data authorization, and there isn't a one-size-fits-all solution.

https://aws.amazon.com/ru/blogs/security/implement-effective-data-authorization-mechanisms-to-secure-your-data-used-in-generative-ai-applications-part-2/

(Use VPN to open from Russia)

#aws
  • 👍 2
  • ❤ 1
  • 🔥 1
Post #1091 485
🔶 RogueOIDC: AWS Persistence and Evasion through attacker-controlled OIDC Identity Provider

This research shows what an attacker can achieve after creating a malicious OIDC identity provider in AWS and how they can do it. The article presents novel techniques and tools for persistence and evasion.

https://www.offensai.com/blog/rogueoidc-aws-persistence-and-evasion-through-attacker-controlled-oidc-identity-provider

(Use VPN to open from Russia)

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →