ar
Feedback
CloudSec Wine

CloudSec Wine

الذهاب إلى القناة على Telegram

All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops

إظهار المزيد
2 260
المشتركون
لا توجد بيانات24 ساعات
+27 أيام
+1430 أيام

جاري تحميل البيانات...

جذب المشتركين
أغسطس '26
أغسطس '26
+24
في 0 قنوات
يوليو '26
+40
في 1 قنوات
Get PRO
يونيو '26
+24
في 0 قنوات
Get PRO
مايو '26
+41
في 2 قنوات
Get PRO
أبريل '26
+38
في 2 قنوات
Get PRO
مارس '26
+81
في 3 قنوات
Get PRO
فبراير '26
+34
في 0 قنوات
Get PRO
يناير '26
+38
في 0 قنوات
Get PRO
ديسمبر '25
+30
في 0 قنوات
Get PRO
نوفمبر '25
+31
في 0 قنوات
Get PRO
أكتوبر '25
+27
في 0 قنوات
Get PRO
سبتمبر '25
+20
في 0 قنوات
Get PRO
أغسطس '25
+31
في 0 قنوات
Get PRO
يوليو '25
+15
في 0 قنوات
Get PRO
يونيو '25
+28
في 0 قنوات
Get PRO
مايو '25
+24
في 3 قنوات
Get PRO
أبريل '25
+26
في 0 قنوات
Get PRO
مارس '25
+17
في 0 قنوات
Get PRO
فبراير '25
+29
في 1 قنوات
Get PRO
يناير '25
+11
في 0 قنوات
Get PRO
ديسمبر '24
+18
في 0 قنوات
Get PRO
نوفمبر '24
+33
في 0 قنوات
Get PRO
أكتوبر '24
+35
في 1 قنوات
Get PRO
سبتمبر '24
+44
في 1 قنوات
Get PRO
أغسطس '24
+47
في 1 قنوات
Get PRO
يوليو '24
+39
في 0 قنوات
Get PRO
يونيو '24
+27
في 0 قنوات
Get PRO
مايو '24
+27
في 0 قنوات
Get PRO
أبريل '24
+55
في 1 قنوات
Get PRO
مارس '24
+42
في 1 قنوات
Get PRO
فبراير '24
+49
في 1 قنوات
Get PRO
يناير '24
+47
في 1 قنوات
Get PRO
ديسمبر '23
+58
في 1 قنوات
Get PRO
نوفمبر '23
+43
في 1 قنوات
Get PRO
أكتوبر '23
+25
في 1 قنوات
Get PRO
سبتمبر '23
+50
في 0 قنوات
Get PRO
أغسطس '23
+45
في 0 قنوات
Get PRO
يوليو '23
+40
في 0 قنوات
Get PRO
يونيو '23
+52
في 0 قنوات
Get PRO
مايو '23
+131
في 0 قنوات
Get PRO
أبريل '23
+27
في 0 قنوات
Get PRO
مارس '23
+59
في 0 قنوات
Get PRO
فبراير '23
+23
في 0 قنوات
Get PRO
يناير '23
+20
في 0 قنوات
Get PRO
ديسمبر '22
+19
في 0 قنوات
Get PRO
نوفمبر '22
+29
في 0 قنوات
Get PRO
أكتوبر '22
+32
في 0 قنوات
Get PRO
سبتمبر '22
+28
في 0 قنوات
Get PRO
أغسطس '22
+48
في 0 قنوات
Get PRO
يوليو '22
+48
في 0 قنوات
Get PRO
يونيو '22
+38
في 0 قنوات
Get PRO
مايو '22
+69
في 0 قنوات
Get PRO
أبريل '22
+27
في 0 قنوات
Get PRO
مارس '22
+16
في 0 قنوات
Get PRO
فبراير '22
+24
في 0 قنوات
Get PRO
يناير '22
+90
في 0 قنوات
Get PRO
ديسمبر '21
+42
في 0 قنوات
Get PRO
نوفمبر '21
+22
في 0 قنوات
Get PRO
أكتوبر '21
+27
في 0 قنوات
Get PRO
سبتمبر '21
+97
في 0 قنوات
Get PRO
أغسطس '21
+53
في 0 قنوات
Get PRO
يوليو '21
+61
في 0 قنوات
Get PRO
يونيو '21
+86
في 0 قنوات
Get PRO
مايو '21
+10
في 0 قنوات
Get PRO
أبريل '21
+15
في 0 قنوات
Get PRO
مارس '21
+29
في 0 قنوات
Get PRO
فبراير '21
+93
في 0 قنوات
Get PRO
يناير '21
+52
في 0 قنوات
Get PRO
ديسمبر '20
+764
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
27 أغسطس0
26 أغسطس+1
25 أغسطس+1
24 أغسطس+1
23 أغسطس0
22 أغسطس0
21 أغسطس0
20 أغسطس+1
19 أغسطس+1
18 أغسطس+1
17 أغسطس0
16 أغسطس+1
15 أغسطس+1
14 أغسطس+2
13 أغسطس+2
12 أغسطس+1
11 أغسطس+4
10 أغسطس0
09 أغسطس0
08 أغسطس+1
07 أغسطس0
06 أغسطس0
05 أغسطس+1
04 أغسطس0
03 أغسطس+1
02 أغسطس+2
01 أغسطس+2
منشورات القناة
🔶 Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway AgentCore Gate
🔶 Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway AgentCore Gateway supports OAuth 2.0, IAM, and API keys natively, but a request Lambda interceptor enables legacy Basic Auth integration. The interceptor validates the inbound JWT, retrieves system credentials from Secrets Manager, and constructs the Basic Auth header before forwarding to the downstream tool. https://aws.amazon.com/ru/blogs/security/implement-custom-authentication-for-tools-integration-using-request-lambda-interceptor-in-agentcore-gateway #aws

2
🤖 LiteLLM Supply Chain Attack: 2,500+ Companies Exposed in the Largest AI Supply Chain Breach of 2026 CloudSEK's research on
🤖 LiteLLM Supply Chain Attack: 2,500+ Companies Exposed in the Largest AI Supply Chain Breach of 2026 CloudSEK's research on the LiteLLM supply chain attack, the largest AI supply chain breach of 2026, names the organizations potentially exposed: 2,500+ companies and 434,000 CI/CD pipelines worldwide. https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines #AI
190
3
🤖 Putting models to the secure coding test: Plan vs default mode Datadog tested Claude Sonnet 5, Composer 2.5, and GPT 5.5 i
🤖 Putting models to the secure coding test: Plan vs default mode Datadog tested Claude Sonnet 5, Composer 2.5, and GPT 5.5 in plan vs. default mode for secure code generation. No meaningful correlation between plan mode and improved security was found; explicit prompt-level security constraints had greater impact than mode selection. https://securitylabs.datadoghq.com/articles/putting-models-to-the-secure-coding-test-plan-vs-default-mode #AI
214
4
🔶 Threat hunt AI: How we built an AI security analyst on AWS for under $500/month Grow Therapy built a Claude-powered threat
🔶 Threat hunt AI: How we built an AI security analyst on AWS for under $500/month Grow Therapy built a Claude-powered threat hunting system on ECS Fargate and Lambda, querying Snowflake and Datadog logs across 15 sources. A five-phase AI pipeline (data gathering, baseline comparison, enrichment, confidence scoring, adversarial validation) reduces false positives. Total cost: under $500/month. https://engineering.growtherapy.com/post/threat-hunt-ai-how-we-built-an-ai-security-analyst-on-aws-for-under-500-month #aws
226
5
⚠️ Going depthfirst: Achieving GitLab RCE via Two Ruby Memory. Corruption Vulnerabilities Researchers chained two memory-safe
⚠️ Going depthfirst: Achieving GitLab RCE via Two Ruby Memory. Corruption Vulnerabilities Researchers chained two memory-safety flaws in Oj, into remote code execution in a Puma worker. The path begins with an attacker-controlled Jupyter notebook and crosses GitLab, ipynbdiff, CRuby, and jemalloc before reaching function-pointer control. https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities #AI
286
6
🤖 Building an Advanced Agentic Harness How to build a production-grade agentic harness using typed Pydantic tools, a DAG pla
🤖 Building an Advanced Agentic Harness How to build a production-grade agentic harness using typed Pydantic tools, a DAG planner with parallel asyncio execution, tiered memory, Planner/Worker/Critic role separation, multi-dimensional budgeting with graceful degradation, and structured tracing for observability. https://data4sci.com/blog/building-an-advanced-agentic-harness #AI
275
7
🔶 A few notes on AWS Nitro Enclaves: KMS integration This third installment in Trail of Bits' Nitro Enclaves series catalogs
🔶 A few notes on AWS Nitro Enclaves: KMS integration This third installment in Trail of Bits' Nitro Enclaves series catalogs passive and active attack classes against enclave-KMS communication, covering CMK substitution, data key swapping, replay attacks, policy misconfigurations, key commitment gaps, and operational risks. https://blog.trailofbits.com/2026/08/05/a-few-notes-on-aws-nitro-enclaves-kms-integration #aws
262
8
🔶 How AWS IAM role manager rethinks the starting point for IAM roles AWS IAM role manager automates IAM role creation within
🔶 How AWS IAM role manager rethinks the starting point for IAM roles AWS IAM role manager automates IAM role creation within supported service consoles, eliminating manual role setup. Using managed role templates and a new AcquireRole API, it provisions and attaches least-privilege roles automatically. Roles remain fully customer-controlled and refinable via IAM Access Analyzer. https://aws.amazon.com/ru/blogs/security/how-aws-iam-role-manager-rethinks-the-starting-point-for-iam-roles #aws
259
9
🤖 Orchestrating AI Code Review at scale Cloudflare built a CI-native AI code review system using OpenCode, orchestrating up
🤖 Orchestrating AI Code Review at scale Cloudflare built a CI-native AI code review system using OpenCode, orchestrating up to 7 specialised agents (security, performance, code quality, etc.) per merge request. https://blog.cloudflare.com/ai-code-review #AI
258
10
🔶 HIPAA Security Rule on AWS AWS released a whitepaper guiding covered entities and business associates on implementing HIPA
🔶 HIPAA Security Rule on AWS AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance. https://aws.amazon.com/ru/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance #aws
337
11
🔴 Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline Google Cloud CISO Chris Betz argues that AI-n
🔴 Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline Google Cloud CISO Chris Betz argues that AI-native threat defense is now a board-level requirement. Boards should govern five areas: business enablement, remediation cycle speed, platform consolidation, contextual vulnerability prioritization, and AI safety policy to enable secure, AI-driven business agility. https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-why-ai-threat-defense-is-the-new-boardroom-baseline #gcp
322
12
👩‍💻 CosmosEscape: Taking Over Every Azure Cosmos DB Wiz Research found CosmosEscape, a critical vulnerability in Azure Cosm
👩‍💻 CosmosEscape: Taking Over Every Azure Cosmos DB Wiz Research found CosmosEscape, a critical vulnerability in Azure Cosmos DB's Gremlin API enabling sandbox escape via .NET reflection. Attackers could obtain a platform-wide Cosmos Master Key granting full read/write access to any customer database and enumeration of all accounts. https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db #azure
302
13
🤖 Before the first prompt: Code execution paths in trusted coding-agent projects Trusted coding-agent projects can execute r
🤖 Before the first prompt: Code execution paths in trusted coding-agent projects Trusted coding-agent projects can execute repository-controlled code before the first user prompt via MCP server configs or PATH hijacking in .claude/settings.json. Developers should treat project trust like running an arbitrary setup script. https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt #AI
338
14
🔶 Investigating Persistence Mechanisms in AWS Rapid7 Labs details four AWS persistence techniques used by attackers: rogue I
🔶 Investigating Persistence Mechanisms in AWS Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps. https://www.rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms #aws
330
15
🤖 AI Worming through Word A coordinated disclosure with MSRC demonstrating a document-borne AI worm in Microsoft Copilot for+1
🤖 AI Worming through Word A coordinated disclosure with MSRC demonstrating a document-borne AI worm in Microsoft Copilot for Word: hidden XPIA prompts in source documents cause Copilot to alter generated content and self-propagate the malicious instructions into downstream documents. https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word #AI
397
16
🤖 A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines An analysis of the security model of Amazo
🤖 A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines An analysis of the security model of Amazon S3 Vectors and of the considerations that arise when it is used as the retrieval layer for LLM applications: access control scope, input validation, metadata integrity, and audit coverage. https://www.offensai.com/blog/amazon-s3-vectors-security-llm-rag-poisoning #AI
346
17
🤖 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to HunggingFace's incident disclosure from last week. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how they investigated with GLM 5.2. https://huggingface.co/blog/agent-intrusion-technical-timeline #AI
1
18
🤖 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to
🤖 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to HunggingFace's incident disclosure from last week. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how they investigated with GLM 5.2. https://huggingface.co/blog/agent-intrusion-technical-timeline #AI
343
19
🤖 Least privilege for AI agents: Identity, access, and tool binding AI agents acting as autonomous multi-system actors requi+1
🤖 Least privilege for AI agents: Identity, access, and tool binding AI agents acting as autonomous multi-system actors require dedicated managed identities, least-privilege task-scoped RBAC, explicit tool allowlists, JIT time-limited entitlements, downstream re-authorization per call, and end-to-end audit logs capturing identity, role, scope, and correlation IDs. https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding #AI
350
20
🤖 Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything Permiso researchers deployed an A
🤖 Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything Permiso researchers deployed an AI agent (Rufio) into the OpenClaw ecosystem and found active malware campaigns in its unvetted skill marketplace (ClawHub), credential-harvesting skills with 377+ downloads, C2 infrastructure, and prompt injection attacks targeting agents holding plaintext credentials to email, Slack, and file systems. https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials #AI
333