CloudSec Wine
الذهاب إلى القناة على Telegram
All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops
إظهار المزيد2 227
المشتركون
لا توجد بيانات24 ساعات
-27 أيام
+230 أيام
أرشيف المشاركات
2 227
👀 Building Slack’s Anomaly Event Response
This article introduces Slack's Anomaly Event Response (AER), an automated security system that detects suspicious activities and terminates user sessions in real-time, reducing detection-to-response gaps from hours to minutes.
https://slack.engineering/building-slacks-anomaly-event-response/
#monitor
2 227
🔐 Blog: A Beginners Guide: Cross-Device Passkeys
Find out more about how passkeys can be used across devices using a mechanism called Hybrid transport.
https://bughunters.google.com/blog/passkeys
#iam
2 227
🔴 Google Looker RCE vulnerabilities: Patch now
Tenable Research discovered two novel vulnerabilities in Google Looker that could allow an attacker to completely compromise a Looker instance.
https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout
#gcp
2 227
👩💻 Weaponizing Whitelists: An Azure Blob Storage Mythic C2 Profile
Mature enterprises lock down egress but often carve out broad exceptions for trusted cloud services. This post shows how reviewing deployment guides can help identify those exceptions and weaponize them with a new Mythic C2 profile called azureBlob.
https://specterops.io/blog/2026/01/30/weaponizing-whitelists-an-azure-blob-storage-mythic-c2-profile/
#azure
2 227
🤖 AI-Assisted Development at Block
Block's AI engineering approach includes: 95% of engineers using AI assistants, providing freedom to explore multiple tools, launching an AI Champions program focused on repo readiness and context engineering, implementing automated PRs, and planning team-based workshops for multi-agent workflows.
https://engineering.block.xyz/blog/ai-assisted-development-at-block
#AI
2 227
⚙️ Stealing Salesforce OAuth Tokens using the WAF
This post details a method for stealing Salesforce OAuth tokens by exploiting an XSS vulnerability and leveraging the Cloudflare Web Application Firewall (WAF).
https://castilho.sh/salesforce-oauth-ato
#saas
2 227
⚙ We should all be using dependency cooldowns
Dependency cooldowns delay automatic dependency updates, providing a free and effective mitigation against most open source supply chain attacks. Tools like Dependabot and Renovate support configurable cooldown periods before adopting new dependency versions.
https://blog.yossarian.net/2025/11/21/We-should-all-be-using-dependency-cooldowns
#cicd
2 227
⚙️ Kube-Policies BinauthZ: Closing the Supply Chain Gap in Kubernetes
Block's BinauthZ plugin extends their OPA-based admission controller to cryptographically verify container image signatures and attestations at Kubernetes admission time, enforcing SLSA using Sigstore/cosign with AWS KMS.
https://engineering.block.xyz/blog/kube-policies-binauthz-closing-the-supply-chain-gap-in-kubernetes
#kubernetes
2 227
Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission
An authorization bypass in Kubernetes RBAC allows for nodes/proxy GET permissions to execute commands in any Pod in the cluster.
https://grahamhelton.com/blog/nodes-proxy-rce
#kubernetes
2 227
⚙ Running Renovate as a GitHub Action (and NO PAT!)
A post explaining how you can run Renovate as a GitHub Action without needing a GitHub Personal Access Token by using Octo STS.
https://www.chainguard.dev/unchained/running-renovate-as-a-github-action
#ci/cd
2 227
👩💻 A new era of agents, a new era of posture
Microsoft Defender introduces AI Security Posture Management for multi-cloud environments, providing visibility and contextual risk assessment across AI agent architectures. It identifies agents connected to sensitive data, susceptible to indirect prompt injection attacks, and operating as coordinators, while offering attack path analysis and actionable hardening recommendations.
https://www.microsoft.com/en-us/security/blog/2026/01/21/new-era-of-agents-new-era-of-posture/
#azure
2 227
👩💻 Linking Privileged Accounts to Identities in Microsoft Defender: Benefits & Use Cases
Microsoft Defender for Identity now allows linking multiple accounts to a single identity, by correlating accounts from different identity providers or linking distinct user accounts, crucial for incident response and remediation.
https://www.cloud-architekt.net/linking-privileged-accounts-in-defender/
#azure
2 227
🔶 CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild
Wiz Research discovered a critical supply chain vulnerability that abused a CodeBuild misconfiguration to take over key AWS GitHub repositories, including the JavaScript SDK powering the AWS Console.
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#aws
2 227
⚙️ Kubernetes v1.35: A Better Way to Pass Service Account Tokens to CSI Drivers
Kubernetes 1.35 introduces beta support for CSI drivers to receive service account tokens via the "secrets" field instead of "volume_context", preventing accidental token logging.
https://kubernetes.io/blog/2026/01/07/kubernetes-v1-35-csi-sa-tokens-secrets-field-beta/
#kubernetes
2 227
⚙ Kubernetes v1.35: Restricting executables invoked by kubeconfigs via exec plugin allowList added to kuberc
Kubernetes v1.35 introduces beta support for restricting credential plugin executables via kuberc configuration. Users can set "credentialPluginPolicy" to AllowAll, DenyAll, or Allowlist, with an optional "credentialPluginAllowlist" to specify permitted binaries, enhancing security against supply-chain attacks.
https://kubernetes.io/blog/2026/01/09/kubernetes-v1-35-kuberc-credential-plugin-allowlist/
#kubernetes
2 227
⚙ A Brief Deep-Dive into Attacking and Defending Kubernetes
This article covers Kubernetes attack and defense techniques. Explores Kubernetes components (API Server, ETCD, kubelet), attack vectors including unauthenticated API access, RBAC misconfigurations, ServiceAccount token abuse, malicious admission controllers, CoreDNS poisoning, writable volume mounts, ETCD compromise, and certificate authority exploitation.
https://heilancoos.github.io/research/2025/12/16/kubernetes.html
#aws
2 227
🔶 Unauthenticated Cluster Takeover in AWS ROSA
A critical vulnerability in AWS ROSA Classic allowed unauthenticated attackers to discover clusters via Certificate Transparency logs, extract cluster UUIDs and owner emails from unauthenticated endpoints, initiate unauthorized cluster transfers, and escalate to AWS account access through ROSA's IAM roles.
https://blog.ryanjarv.sh/2026/01/05/unauth-aws-rosa-cluster-takeover.html
(Use VPN to open from Russia)
#aws
2 227
🔶 pathfinding.cloud
An AWS IAM Privilege Escalation Path Library. You can also refer to the companion blog post.
https://github.com/DataDog/pathfinding.cloud
#aws
2 227
🔶 BadPods Series: Everything Allowed on AWS EKS
How to exploit misconfigured Kubernetes pods on AWS EKS using BishopFox's BadPods "everything-allowed" manifest. Shows container escape via chroot, lateral movement using nsenter, and cloud credential theft via IMDS.
https://cybersecnerds.com/badpods-series-everything-allowed-on-aws-eks/
#aws
2 227
👩💻 Azure Seamless SSO: When Cookie Theft Doesn’t Cut It
The cookie crumbled when it expired, but the attack path didn't. Learn how BloodHound graph analysis and Azure Seamless SSO enabled pivoting into the cloud.
https://specterops.io/blog/2025/12/11/azure-seamless-sso-when-cookie-theft-doesnt-cut-it/
#azure
متاح الآن! بحث تيليغرام 2025 — أهم رؤى العام 
