TGViewer
Channel Public Channel
CloudSec Wine

CloudSec Wine

@cloud_sec

All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Subscribers
2.27K
Photos
1.1K
Videos
0
Links
1.4K

Showing posts older than #1230 · Back to latest

Older Posts 20 shown
Post #1229 475
👩‍💻 OAuthSeeker: Leveraging OAuth Phishing for Initial Access and Lateral Movement on Red Team Engagements

The Praetoran Labs team researched initial access vectors for red team engagements, focusing on malicious applications distributed through platforms like the Microsoft Store, including OAuth applications and malicious Outlook extensions.

https://www.praetorian.com/blog/oauthseeker-leveraging-oauth-phishing-for-initial-access-and-lateral-movement-on-red-team-engagements/

#azure
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1227 426
🔶 Under the Hood of Amazon ECS on EC2: Agents, IAM Roles, and Task Isolation | Naor Haziz

This deep-dive explores Amazon ECS on EC2's internals, focusing on the ECS agent's role, IAM credential delivery mechanisms, and task isolation boundaries between containers sharing the same host.

https://naorhaziz.com/posts/under-the-hood-of-amazon-ecs/

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1222 402
👩‍💻 Breaking Down Azure DevOps: Techniques for Extracting Pipeline Credentials

This article explores techniques for extracting credentials from Azure DevOps pipelines, including workload identity federation tokens and service connection secrets, while discussing potential impacts on Terraform Cloud and GitHub resources.

https://labs.reversec.com/posts/2025/07/breaking-down-azure-devops-techniques-for-extracting-pipeline-credentials

#azure
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1219 419
🔶 An Arrow to the Heel: Abusing Default Machine Joining to Domain Permissions to Attack AWS Managed Active Directory

Discover critical AWS Managed Active Directory security vulnerabilities enabling RBCD attacks via ms-ds-MachineAccountQuota. Learn mitigation strategies and detection methods for AWS Directory Service environments.

https://permiso.io/blog/abusing-default-machine-joining-to-domain-permissions-to-attack-aws-managed-active-directory

(Use VPN to open from Russia)

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1212 422
🔴 Zigazoo too, Another Firebase Boogaloo

Zigazoo, a social network for kids, has been found to have significant security vulnerabilities, including unauthorized access to user records, content, and account escalation, all related to Firebase.

https://amenbreakpoint.com/posts/zigazoo/

#gcp
  • ❤ 1
  • 👍 1
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →