en
Feedback
CloudSec Wine

CloudSec Wine

Open in Telegram

All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops

Show more
2 227
Subscribers
No data24 hours
-27 days
+230 days
Posts Archive
๐Ÿ”ท Free Microsoft 365 subscriptions for learning purposes You can get a free Microsoft 365 subscription with 25 user licenses
๐Ÿ”ท Free Microsoft 365 subscriptions for learning purposes You can get a free Microsoft 365 subscription with 25 user licenses to learn and create automations. https://developer.microsoft.com/en-us/microsoft-365/dev-program #azure

๐Ÿ”ถ When MFA becomes SFA A particular case where possession of an AWS access key/secret key alone was equivalent to possession
๐Ÿ”ถ When MFA becomes SFA A particular case where possession of an AWS access key/secret key alone was equivalent to possession of those keys and a previously configured MFA. * P. S. use VPN for Russian IPs * https://www.mwrcybersec.com/when-mfa-becomes-sfa #aws

๐Ÿ”ด GhostToken: Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts The v
๐Ÿ”ด GhostToken: Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts The vulnerability could allow threat actors to change a malicious application to be invisible and unremovable, effectively leaving the victim's Google account infected with a trojan app forever. https://astrix.security/ghosttoken-exploiting-gcp-application-infrastructure-to-create-invisible-unremovable-trojan-app-on-google-accounts #gcp

๐Ÿ”ท Azure Threat Research Matrix The purpose of the Azure Threat Research Matrix (ATRM) is to conceptualize the known tactics,
๐Ÿ”ท Azure Threat Research Matrix The purpose of the Azure Threat Research Matrix (ATRM) is to conceptualize the known tactics, techniques, and procedures (TTP) that adversaries may use against the Azure platform. https://microsoft.github.io/Azure-Threat-Research-Matrix #azure

๐Ÿ”ถ Detecting the Use of Stolen AWS Lambda Credentials A novel technique which uses AWS CloudTrail to detect the use of stolen
๐Ÿ”ถ Detecting the Use of Stolen AWS Lambda Credentials A novel technique which uses AWS CloudTrail to detect the use of stolen credentials. https://www.secureworks.com/research/detecting-the-use-of-stolen-aws-lambda-credentials #aws

๐Ÿ”ถ๐Ÿ”ท๐Ÿ”ด Cloud Red Teaming: AWS Initial Access & Privilege Escalation Slides from a session that covered the latest cloud focus
๐Ÿ”ถ๐Ÿ”ท๐Ÿ”ด Cloud Red Teaming: AWS Initial Access & Privilege Escalation Slides from a session that covered the latest cloud focused attack vectors and described viable strategies on how to detect their malicious usage within your cloud environments. https://speakerdeck.com/tweekfawkes/cloud-red-teaming-aws-initial-access-and-privilege-escalation #aws #azure #gcp

๐Ÿ”ด Asset Key Thief security vulnerability technical details A persistent Service Account private key exfiltration privilege e
๐Ÿ”ด Asset Key Thief security vulnerability technical details A persistent Service Account private key exfiltration privilege escalation technique that potentially affected Google Cloud Service Accounts, now remediated promptly by the Google Cloud team. https://engineering.sada.com/asset-key-thief-disclosure-cfae4f1778b6 #gcp

๐Ÿ”ถ New Phone, Who Dis? How Cloud Environments Are Exploited for Smishing Campaigns Commodity threat actors have recently begu
๐Ÿ”ถ New Phone, Who Dis? How Cloud Environments Are Exploited for Smishing Campaigns Commodity threat actors have recently begun to exploit cloud environments for smishing campaigns, employing techniques strikingly similar to those used in SES enumeration and abuse. https://permiso.io/blog/s/smishing-attack-on-aws-sms-new-phone-who-dis #aws

๐Ÿ”ท Hacking Your Cloud: Tokens Edition 2.0 Techniques attackers might use to exploit cloud tokens and gain access to resources
๐Ÿ”ท Hacking Your Cloud: Tokens Edition 2.0 Techniques attackers might use to exploit cloud tokens and gain access to resources. Strong token management, limiting privileges, and token revocation policies help mitigate risks. https://www.trustedsec.com/blog/hacking-your-cloud-tokens-edition-2-0 #azure

๐Ÿ”ด How to identify and reduce costs of your Google Cloud observability in Cloud Monitoring A cost savings guide for Cloud Mon
๐Ÿ”ด How to identify and reduce costs of your Google Cloud observability in Cloud Monitoring A cost savings guide for Cloud Monitoring. https://cloud.google.com/blog/products/management-tools/learn-to-understand-and-reduce-cloud-monitoring-costs #gcp

๐Ÿ”ถ Privilege escalation in AWS Elastic Kubernetes Service An interesting privilege escalation scenario in Kubernetes (EKS) in
๐Ÿ”ถ Privilege escalation in AWS Elastic Kubernetes Service An interesting privilege escalation scenario in Kubernetes (EKS) involving NodeRestriction. https://blog.calif.io/p/privilege-escalation-in-eks #aws

๐Ÿ”ท Building a secure Azure reference architecture with Terraform A reference architecture including several components, such
๐Ÿ”ท Building a secure Azure reference architecture with Terraform A reference architecture including several components, such as a virtual network, a bastion host, a load balancer, and a cluster of virtual machines running a web application. https://www.hashicorp.com/blog/building-a-secure-azure-reference-architecture-with-terraform #azure

๐Ÿ”ถ The Unholy Marriage of AWS IAM Roles and Instance Profiles Post explaining IAM Roles and Instance Profiles, how to create
๐Ÿ”ถ The Unholy Marriage of AWS IAM Roles and Instance Profiles Post explaining IAM Roles and Instance Profiles, how to create and manage them, and attach them to EC2 instances to grant permissions to access AWS services while adhering to security best practices. https://www.uptycs.com/blog/aws-iam-roles-instance-profiles #aws

๐Ÿ”ท From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys
๐Ÿ”ท From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys How the Orca Security team discovered a critical exploitation path, utilizing Microsoft Azure shared key authorization, and provide key mitigation steps. https://orca.security/resources/blog/azure-shared-key-authorization-exploitation #azure

๐Ÿ”ถ Automate IAM credential reports for large AWS Organizations How to manage credentials with many accounts, automate IAM cre
๐Ÿ”ถ Automate IAM credential reports for large AWS Organizations How to manage credentials with many accounts, automate IAM credential reports, and consolidate the results. https://aws.amazon.com/blogs/infrastructure-and-automation/automate-iam-credential-reports-for-large-aws-organizations #aws

๐Ÿ”ด How to secure digital assets with multi-party computation and Confidential Space To help customers use multi-party computa
๐Ÿ”ด How to secure digital assets with multi-party computation and Confidential Space To help customers use multi-party computation and Confidential Space, GCP described a reference architecture for implementing MPC-compliant blockchain signing. https://cloud.google.com/blog/products/identity-security/how-to-secure-digital-assets-with-multi-party-computation-and-confidential-space #gcp

๐Ÿ”ถ Two Minor Cross-Tenant Vulnerabilities in AWS App Runner These vulnerabilities leaked configuration information across ten
๐Ÿ”ถ Two Minor Cross-Tenant Vulnerabilities in AWS App Runner These vulnerabilities leaked configuration information across tenant boundaries. While they are both minor issues, they further demonstrate that undocumented AWS APIs have lacked the scrutiny of AWS as well as the cloud security community. https://frichetten.com/blog/minor-cross-tenant-vulns-app-runner #aws

๐Ÿ”ถ Containing Compromised EC2 Credentials Without (Hopefully) Breaking Things There are multiple techniques for containing co
๐Ÿ”ถ Containing Compromised EC2 Credentials Without (Hopefully) Breaking Things There are multiple techniques for containing compromised instance credentials. The easy ones are the most likely to break things, but there are creative options to lock out attackers without breaking applications. https://www.firemon.com/containing-compromised-ec2-credentials-without-hopefully-breaking-things #aws

๐Ÿ”ถ Exploring Amazon VPC Lattice AWS has recently released VPC Lattice to General Availability. This post walks through creati
๐Ÿ”ถ Exploring Amazon VPC Lattice AWS has recently released VPC Lattice to General Availability. This post walks through creating a simple VPC Lattice service using CloudFormation, and takes a look at the service overall. https://onecloudplease.com/blog/exploring-amazon-vpc-lattice #aws

๐Ÿ”ท Introducing Microsoft Security Copilot: Empowering defenders at the speed of AI Security Copilot combines an advanced larg
๐Ÿ”ท Introducing Microsoft Security Copilot: Empowering defenders at the speed of AI Security Copilot combines an advanced large language model (LLM) with a security-specific model from Microsoft. This security-specific model in turn incorporates a set of security-specific skills and is informed by Microsoft's unique global threat intelligence. Security Copilot runs on Azure's infrastructure. https://blogs.microsoft.com/blog/2023/03/28/introducing-microsoft-security-copilot-empowering-defenders-at-the-speed-of-ai #azure