CloudSec Wine
前往频道在 Telegram
All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops
显示更多2 275
订阅者
无数据24 小时
+17 天
+1130 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
十月 '2610月 '26
十月 '26
+3
在0个频道中
九月 '26
+38
在1个频道中
Get PRO
八月 '26
+25
在0个频道中
Get PRO
七月 '26
+40
在1个频道中
Get PRO
六月 '26
+24
在0个频道中
Get PRO
五月 '26
+41
在2个频道中
Get PRO
四月 '26
+38
在2个频道中
Get PRO
三月 '26
+81
在3个频道中
Get PRO
二月 '26
+34
在0个频道中
Get PRO
一月 '26
+38
在0个频道中
Get PRO
十二月 '25
+30
在0个频道中
Get PRO
十一月 '25
+31
在0个频道中
Get PRO
十月 '25
+27
在0个频道中
Get PRO
九月 '25
+20
在0个频道中
Get PRO
八月 '25
+31
在0个频道中
Get PRO
七月 '25
+15
在0个频道中
Get PRO
六月 '25
+28
在0个频道中
Get PRO
五月 '25
+24
在3个频道中
Get PRO
四月 '25
+26
在0个频道中
Get PRO
三月 '25
+17
在0个频道中
Get PRO
二月 '25
+29
在1个频道中
Get PRO
一月 '25
+11
在0个频道中
Get PRO
十二月 '24
+18
在0个频道中
Get PRO
十一月 '24
+33
在0个频道中
Get PRO
十月 '24
+35
在1个频道中
Get PRO
九月 '24
+44
在1个频道中
Get PRO
八月 '24
+47
在1个频道中
Get PRO
七月 '24
+39
在0个频道中
Get PRO
六月 '24
+27
在0个频道中
Get PRO
五月 '24
+27
在0个频道中
Get PRO
四月 '24
+55
在1个频道中
Get PRO
三月 '24
+42
在1个频道中
Get PRO
二月 '24
+49
在1个频道中
Get PRO
一月 '24
+47
在1个频道中
Get PRO
十二月 '23
+58
在1个频道中
Get PRO
十一月 '23
+43
在1个频道中
Get PRO
十月 '23
+25
在1个频道中
Get PRO
九月 '23
+50
在0个频道中
Get PRO
八月 '23
+45
在0个频道中
Get PRO
七月 '23
+40
在0个频道中
Get PRO
六月 '23
+52
在0个频道中
Get PRO
五月 '23
+131
在0个频道中
Get PRO
四月 '23
+27
在0个频道中
Get PRO
三月 '23
+59
在0个频道中
Get PRO
二月 '23
+23
在0个频道中
Get PRO
一月 '23
+20
在0个频道中
Get PRO
十二月 '22
+19
在0个频道中
Get PRO
十一月 '22
+29
在0个频道中
Get PRO
十月 '22
+32
在0个频道中
Get PRO
九月 '22
+28
在0个频道中
Get PRO
八月 '22
+48
在0个频道中
Get PRO
七月 '22
+48
在0个频道中
Get PRO
六月 '22
+38
在0个频道中
Get PRO
五月 '22
+69
在0个频道中
Get PRO
四月 '22
+27
在0个频道中
Get PRO
三月 '22
+16
在0个频道中
Get PRO
二月 '22
+24
在0个频道中
Get PRO
一月 '22
+90
在0个频道中
Get PRO
十二月 '21
+42
在0个频道中
Get PRO
十一月 '21
+22
在0个频道中
Get PRO
十月 '21
+27
在0个频道中
Get PRO
九月 '21
+97
在0个频道中
Get PRO
八月 '21
+53
在0个频道中
Get PRO
七月 '21
+61
在0个频道中
Get PRO
六月 '21
+86
在0个频道中
Get PRO
五月 '21
+10
在0个频道中
Get PRO
四月 '21
+15
在0个频道中
Get PRO
三月 '21
+29
在0个频道中
Get PRO
二月 '21
+93
在0个频道中
Get PRO
一月 '21
+52
在0个频道中
Get PRO
十二月 '20
+764
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 06 十月 | +1 | |||
| 05 十月 | 0 | |||
| 04 十月 | 0 | |||
| 03 十月 | 0 | |||
| 02 十月 | +2 | |||
| 01 十月 | 0 |
频道帖子
🤖 Securing the software factory at machine speed
GitLab's CISO argues that agentic AI development requires security, governance, and guardrails embedded in the SDLC execution path. The key metric is time from detection to verified remediation, driven to machine speed using AI-powered triage, constrained agent identities, and continuous scanning.
https://about.gitlab.com/blog/securing-the-software-factory-at-machine-speed
#AI
| 2 | 🤖 Throw Away the Playbook: Security in the AI-Native SDLC
We, as an industry, should have the courage to throw away the playbooks we've been working on for the past 20+ years and create new (and better) ones for the AI era.
https://blog.marcolancini.it/2026/blog-ai-sdlc
#AI | 158 |
| 3 | 🔴 Strengthen your CI/CD pipeline with new Secure Source Manager capabilities
Google Cloud Secure Source Manager adds two GA features: a Code Owners system enabling per-file and per-branch PR approval governance with nestable CODEOWNERS files, and Developer Connect integration for private-network CI/CD connectivity using Private Service Connect and VPC Service Controls.
https://cloud.google.com/blog/products/identity-security/strengthen-your-cicd-pipeline-with-new-secure-source-manager-capabilities
#gcp | 232 |
| 4 | 🔶 Exploring the new AWS Sign Up experience
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
https://www.wiz.io/blog/exploring-the-new-aws-sign-up-experience
#aws | 235 |
| 5 | 🤖 Hacking OpenAI
Researchers chained a libheif heap buffer overflow (via Discourse/ImageMagick image upload) with an OpenAI SSO misconfiguration to achieve RCE on community.openai.com, take over employee ChatGPT/Codex accounts, and access OpenAI's internal GitHub monorepo.
https://www.hacktron.ai/blog/hacking-openai
#AI | 253 |
| 6 | 👩💻 How to secure edge AI in customer-owned environments
Edge AI shifts trust responsibility to customers who operate more of the AI stack outside provider control. Organizations must verify runtimes via attestation, validate AI artifact provenance, constrain model actions through deterministic mediation, and bind sensitive assets only to trusted, evidence-verified environments.
https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments
#azure | 239 |
| 7 | 🤖 Containers Are No Longer a Security Boundary
AI-accelerated kernel vuln discovery (5,976 CVEs in 2026) has made container escapes trivial. CVE-2026-80521, a Linux AF_UNIX use-after-free, demonstrates a full container escape.
https://depthfirst.com/research/containers-are-no-longer-safe
#AI | 255 |
| 8 | 🔶 Introducing Amazon EBS Volume Clones across AWS account
AWS introduces Amazon EBS Volume Clones with cross-account copy, so you can create copies of your EBS volumes into other AWS accounts and optionally re-encrypt them with an AWS Key Management Service (AWS KMS) key in the target account.
https://aws.amazon.com/ru/blogs/aws/introducing-amazon-ebs-volume-clones-across-aws-accounts
#aws | 320 |
| 9 | 🤖 DeepSeek Harness Vulnerability. Lets AI Agents Escape Their Own Sandbox
CVE-2026-82533 (CVSS 9.4) in DeepSeek Harness lets a sandboxed AI agent escape confinement via a single curl call to the unauthenticated local API, spoofing the Host header to elevate its session to danger-full-access.
https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape
#AI | 507 |
| 10 | 🤖 Hacking AI customer service agents
Techniques for attacking AI customer service agents: email spoofing to hijack agent actions, MFA bypass via email normalization and IVR channel-switching, email address smuggling via RFC comments for IDOR, OTP exfiltration via inbox-monitoring agents, asymmetric MIME content, conversation forgery, and RAG knowledge base poisoning.
https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents
#AI | 312 |
| 11 | 🤖 OpenAI's Defense Factory
OpenAI's Defense Factory is a continuous, agent-first vulnerability detection and remediation pipeline using Codex and specialized cyber models (Daybreak Blue/Red). It automates inventory, triage, dynamic validation, ownership assignment, and verified patching, achieving 0.81% false-positive rate and 0.53% fix rollback rate.
https://openai.com/ru-RU/the-defense-factory
#AI | 312 |
| 12 | 🤖 Detecting and countering misuse of AI: September 2026
Anthropic's September 2026 threat report covers disrupted misuse of Claude (Dec 2025-Aug 2026) across seven harm areas: AI-augmented cyber ops by state and criminal actors, influence operations across six continents, surveillance platforms targeting dissidents, conventional weapons software development, dual-use biological research, fraud/scams, and illicit distillation by PRC AI labs including Alibaba, DeepSeek, Moonshot, and Zhipu.
https://www.anthropic.com/threat-intelligence-report-september-2026
#AI | 348 |
| 13 | 🤖 ASCII smuggling crosses over from AI prompt injection to phishing evasion
Microsoft researchers discovered a high-volume phishing campaign that repurposed ASCII smuggling to split financial keywords like "funding" and evade email filters, generating over 2.3 million messages daily at its February 2026 peak.
https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion
#AI | 359 |
| 14 | 🤖 GTIG AI Threat Tracker: From Prompting to Autonomy
This AI threat update provides GTIG's findings on adversarial misuse of AI including Gemini and other non-Google tools.
https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
#AI | 362 |
| 15 | 🔶 Agentic SOC alert triage: 60% to 92% AI accuracy
Elastic's InfoSec team describes how enriching a three-agent SOC triage pipeline with per-rule investigation guides, user risk data, and 30 days of historical case verdicts lifted AI alert accuracy from 60% to 92%, enabling analysts to close most alerts with a single Slack button click.
https://www.elastic.co/security-labs/blog/alert-triage-agentic-soc-self-correcting-agents
#aws | 335 |
| 16 | 🔶 Incident response guide for AWS CloudTrail investigations
AWS's Security Incident Response Team (SIRT) walks through two real-world CloudTrail investigation scenarios, cross-account S3 data deletion with ransomware implications and cryptocurrency mining via stolen console credentials, teaching investigators how to read key log fields, recognize attacker patterns, and apply practical response checklists. You can also check out Part 2.
https://aws.amazon.com/ru/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1
#aws | 300 |
| 17 | 🔶 A scenario to evaluate your Agentic SOC
A downloadable multi-source log dataset built around a 7-phase GitHub Actions cache poisoning → Kubernetes → AWS attack chain, used to benchmark agentic SOC harnesses.
https://unsecure.sh/blog/agentic-soc-scenario/
#aws | 301 |
| 18 | 🔶 Automate IAM Identity Center governance with continuous discovery and reporting
A walkthrough deploying two AWS CDK stacks for IAM Identity Center governance: a reporting stack (EventBridge, Step Functions, Lambda, DynamoDB, API Gateway, S3) for automated daily discovery and CSV export, and a remediation stack for real-time event-driven enforcement and SNS notifications on non-compliant application assignments.
https://aws.amazon.com/ru/blogs/security/automate-iam-identity-center-governance-with-continuous-discovery-and-reporting
#aws | 337 |
| 19 | 🔶 Extend your data perimeter to the AWS Management Console with Private Access
AWS Management Console Private Access is now GA, routing all console traffic (auth, static assets, service APIs) through AWS PrivateLink VPC endpoints with no internet path required. VPC endpoint policies and Sign-In RCPs enforce identity, resource, and network perimeter controls on interactive console sessions.
https://aws.amazon.com/ru/blogs/security/extend-your-data-perimeter-to-the-aws-management-console-with-private-access
#aws | 343 |
| 20 | 🤖Amazon Kiro: AI Is Breaking Vulnerability Disclosure Processes
A prompt injection flaw in Amazon Kiro IDE v0.7.45 allowing attacker-controlled repository content to exfiltrate sensitive data via the powersRecommendationUrl setting and Kiro Powers, exploitable in both trusted and untrusted workspaces.
https://mindgard.ai/blog/amazon-kiro-data-exfiltration
#AI | 298 |
