TGViewer
Channel Public Channel
CloudSec Wine

CloudSec Wine

@cloud_sec

All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Subscribers
2.27K
Photos
1.1K
Videos
0
Links
1.4K

Showing posts older than #1457 · Back to latest

Older Posts 13 shown
Post #1454 425
🤖 Comparing AI Application Security Testing Platforms

Doyensec compared Aikido Attack AI Pentest and XBOW Lightspeed for web app vulnerability detection, evaluating true/false positives, configuration, report quality, cost, speed, and impact on tested applications. Full findings available as a PDF.

#AI
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1450 392
🌩 When Background AI Agents Become a Security Boundary Problem

Claude Code's background sessions, supervisor process, CLAUDE_CONFIG_DIR override, scheduled tasks, and Markdown-based agent definitions can be chained post-foothold to deploy a persistent, nearly invisible C2 agent evading standard EDR binary-focused detection.

https://www.originhq.com/research/background-c2-agent

#ClaudeCode
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1448 403
🔶 Global S3: Another C2 Channel for AgentCore Code Interpreters

AWS AgentCore Code Interpreters in Sandbox mode allow unrestricted global S3 access (including cross-account, public/presigned URLs), enabling a bidirectional C2 channel via S3 polling, demonstrated as a full reverse shell PoC. Mitigation: use VPC mode with S3 Gateway Endpoints and strict endpoint policies.

https://sonraisecurity.com/blog/global-s3-another-c2-channel-for-agentcore-code-interpreters

#aws
  • ❤ 2
  • 👍 1
  • 🔥 1
Post #1446 416
👩‍💻 The expendable extension name: Azure VMAccess naming chaos, password resets, and a detection gap

The Sysdig Threat Research Team uncovered a detection gap in Azure VM password resets that allows attackers to evade name-based detections by assigning arbitrary VM extension names. Learn how the flaw works, why Microsoft's documented detection guidance failed during testing, and what defenders should monitor instead.

https://www.sysdig.com/blog/the-expendable-extension-name-azure-vmaccess-naming-chaos-password-resets-and-a-detection-gap

#azure
  • ❤ 2
  • 👍 1
  • 🔥 1
Post #1445 407
Аудитные логи в облаке — отдельная распределённая система со своими требованиями к надёжности и стоимости хранения, а не «таблица с событиями».

Команда MWS Cloud Platform выложила подробный разбор архитектуры своего сервиса: от библиотеки, которую подключают сервисы облака, до хранилища на Apache Iceberg и движка StarRocks, с объяснением, почему выбрали именно такой набор технологий и где спрятаны неочевидные грабли.

Полезно всем, кто разрабатывает ИБ-инструменты, работает с большим количеством событий или просто интересуется инструментами безопасности в облаке.

Читать статью на Хабре

#реклама
  • ❤ 2
  • 👍 2
  • 🔥 2
Post #1443 389
🔶 CISA Admin Leaked AWS GovCloud Keys on Github

A Nightwing contractor's public GitHub repo ("Private-CISA"), active since November 2025, exposed plaintext AWS GovCloud admin keys, Firefox-saved passwords, kubeconfig, and Artifactory credentials for CISA internal systems, with GitHub's secret-scanning protections deliberately disabled.

https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1438 480
🌩 Claude Code MCP Token Theft: MitM Attack Explained

Mitiga Labs shows how Claude Code MCP configuration can be hijacked through ~/.claude.json to steal OAuth tokens, persist through rotation, and hide in trusted SaaS activity.

https://www.mitiga.io/blog/claude-code-mcp-token-theft-mitm

#ClaudeCode
  • ❤ 1
  • 👍 1
  • 🔥 1
Post #1436 408
🔶 Authorization Bypass in Amazon Quick: Unauthorized AI Chat Agent Usage

An authorization bypass in Amazon Quick's AI Chat Agents that allowed users to access and interact with AI agents despite explicit administrative restrictions. AWS responded by deploying a fix without notifying customers, classified the issue as “none,” and did not publish an advisory.

https://www.fogsecurity.io/blog/authorization-bypass-in-amazon-quick-ai-agents

#aws
  • ❤ 2
  • 👍 1
  • 🔥 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →