fa
Feedback
CloudSec Wine

CloudSec Wine

رفتن به کانال در Telegram

All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops

نمایش بیشتر
2 226
مشترکین
-124 ساعت
-27 روز
-230 روز
آرشیو پست ها
🔶🔷🔴 Dear, cloud family! Wishing you a New Year filled with innovative solutions, seamless deployments, and sky‑high succes
🔶🔷🔴 Dear, cloud family! Wishing you a New Year filled with innovative solutions, seamless deployments, and sky‑high success! May your cloud infrastructure be always resilient and your downtime — zero. Happy New Year 2026! We'll be taking a short break and returning in a few days to bring you new, professional content. #HappyNewYear

🔶 boto3-refresh-session A simple Python package for refreshing AWS temporary credentials in boto3 automatically https://gith
🔶 boto3-refresh-session A simple Python package for refreshing AWS temporary credentials in boto3 automatically https://github.com/michaelthomasletts/boto3-refresh-session #aws

👩‍💻 ATEAM A Python reconnaissance tool designed to discover Azure services and attribute tenant ownership information based
👩‍💻 ATEAM A Python reconnaissance tool designed to discover Azure services and attribute tenant ownership information based on their responses. https://github.com/NetSPI/ATEAM #azure

Что загадывает DevOps на Новый год? ⏺чтобы кластер обновлялся без ночных алертов ⏺сеть работала стабильно и предсказуемо ⏺апг
Что загадывает DevOps на Новый год? ⏺чтобы кластер обновлялся без ночных алертов ⏺сеть работала стабильно и предсказуемо ⏺апгрейд кластера не превращался в вечер с release notes Разработчики Managed Kubernetes в облаке MWS Cloud Platform ⬜ знают все ваши тайные желания и готовы упростить вашу DevOps-рутину.
С Managed Kubernetes вы получаете: ⏺готовый кластер за несколько минут без сложной настройки ⏺управление жизненным циклом кластера и нод ⏺ автоматическое масштабирование под нагрузку ⏺ нативную работу с сетью и storage через CCM / CSI ⏺ централизованное управление доступами через IAM
🎄🎁 Попробуйте с грантом до 10 000 ₽ Попробовать

🔶 aws-extend-switch-roles Extend your AWS IAM switching roles by Chrome extension, Firefox add-on, or Edge add-on. https://g
🔶 aws-extend-switch-roles Extend your AWS IAM switching roles by Chrome extension, Firefox add-on, or Edge add-on. https://github.com/tilfinltd/aws-extend-switch-roles #aws

🔶🔷🔴 tokenex A Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support fo
🔶🔷🔴 tokenex A Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azure, OCI, Kubernetes, and OAuth2. You can also refer to the companion blog post. https://github.com/riptideslabs/tokenex #aws #azure #gcp

🔶 IAMhounddog A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportu
🔶 IAMhounddog A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS accounts. https://github.com/VirtueSecurity/IAMhounddog #aws

🔶 yams A Go library, server, and CLI providing foundational capabilities to simulate access for AWS IAM policies. https://gi
🔶 yams A Go library, server, and CLI providing foundational capabilities to simulate access for AWS IAM policies. https://github.com/nsiow/yams #aws

🔶 aws-finops-dashboard A terminal-based AWS cost and resource dashboard which provides an overview of AWS spend by account,
+1
🔶 aws-finops-dashboard A terminal-based AWS cost and resource dashboard which provides an overview of AWS spend by account, service-level breakdowns, budget tracking, and EC2 instance summaries. https://github.com/ravikiranvm/aws-finops-dashboard #aws

🔶 AWS Builder Center A portal collecting hands-on workshops crafted by AWS experts to gain practical experience and solve re
🔶 AWS Builder Center A portal collecting hands-on workshops crafted by AWS experts to gain practical experience and solve real business challenges. https://builder.aws.com/build/workshops (Use VPN to open from Russia) #aws

🔶 AWS Lambda Managed Instances: A Security Overview An initial security overview of AWS Lambda Managed Instances, exploring
🔶 AWS Lambda Managed Instances: A Security Overview An initial security overview of AWS Lambda Managed Instances, exploring the Bottlerocket-based architecture, the 'Elevator' components, and security insights for this new compute model. https://www.offensai.com/blog/aws-lambda-managed-instances-security-overview (Use VPN to open from Russia) #aws

🔶 All Paths Lead to Your Cloud: A Mapping of Initial Access Vectors to Your AWS Environment Post which analyzes AWS initial
🔶 All Paths Lead to Your Cloud: A Mapping of Initial Access Vectors to Your AWS Environment Post which analyzes AWS initial access vectors through identity-driven misconfigurations, categorizing them into service exposure (Lambda, EC2, ECR, DataSync) and access by design (IAM/STS, IoT, Cognito) vulnerabilities that compromise cloud perimeter security. https://www.paloaltonetworks.com/blog/cloud-security/aws-initial-access-cloud-perimeter-security/ (Use VPN to open from Russia) #aws

🔶 Exploiting AWS IAM Eventual Consistency for Persistence AWS IAM eventual consistency creates a 4-second window where delet
+1
🔶 Exploiting AWS IAM Eventual Consistency for Persistence AWS IAM eventual consistency creates a 4-second window where deleted AWS access keys can still work. Learn how attackers exploit this and how to mitigate it. https://www.offensai.com/blog/aws-iam-eventual-consistency-persistence (Use VPN to open from Russia) #aws

👩‍💻 Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users Datadog identified an
👩‍💻 Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users Datadog identified an active adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users. The campaign uses lookalike domains, proxies legitimate authentication pages, injects JavaScript to steal credentials and session tokens, and can bypass non-phishing-resistant MFA. https://securitylabs.datadoghq.com/articles/investigating-an-aitm-phishing-campaign-m365-okta/ #azure

🔴 VPC Flow Logs for Cross-CloudNetwork With VPC Flow Logs, now you can monitor critical network traffic moving between your
🔴 VPC Flow Logs for Cross-CloudNetwork With VPC Flow Logs, now you can monitor critical network traffic moving between your on-prem infrastructure, cross-cloudresources, and Google Cloud. https://cloud.google.com/blog/products/networking/vpc-flow-logs-for-cross-cloud-network/ #gcp

🔶 Amazon CloudWatch introduces unified data management and analytics for operations, security, and compliance CloudWatch can
🔶 Amazon CloudWatch introduces unified data management and analytics for operations, security, and compliance CloudWatch can automatically normalize and process data to offer consistency across sources with built-in support for Open Cybersecurity Schema Framework (OCSF) and Open Telemetry (OTel) formats, so you can focus on analytics and insights. https://aws.amazon.com/ru/blogs/aws/amazon-cloudwatch-introduces-unified-data-management-and-analytics-for-operations-security-and-compliance/ (Use VPN to open from Russia) #aws

🔶 Introducing AWS Lambda Managed Instances: Serverless simplicity with EC2 flexibility Run Lambda functions on EC2 compute w
🔶 Introducing AWS Lambda Managed Instances: Serverless simplicity with EC2 flexibility Run Lambda functions on EC2 compute while maintaining serverless simplicity—enabling access to specialized hardware and cost optimizations through EC2 pricing models, with AWS handling all infrastructure management. https://aws.amazon.com/ru/blogs/aws/introducing-aws-lambda-managed-instances-serverless-simplicity-with-ec2-flexibility/ (Use VPN to open from Russia) #aws

🔶 Amazon CloudFront mTLS with open-source serverless CA A step-by-step guide on implementing mTLS for Amazon CloudFront usin
🔶 Amazon CloudFront mTLS with open-source serverless CA A step-by-step guide on implementing mTLS for Amazon CloudFront using our open-source cloud CA. https://medium.com/@paulschwarzenberger/amazon-cloudfront-mtls-with-open-source-serverless-ca-f49ce2bc9874 (Use VPN to open from Russia) #aws

👩‍💻 Backdooring Managed Identities via Azure API Management Azure API Management exposes managed identity certificates with
👩‍💻 Backdooring Managed Identities via Azure API Management Azure API Management exposes managed identity certificates with private keys in plaintext through an undocumented configuration API used by self-hosted gateways. Attackers with gateway keys can extract these certificates for persistent backdoor access. https://dazesecurity.io/blog/apimMIVuln (Use VPN to open from Russia) #azure

🔶 Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region AWS announces VPC en
🔶 Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region AWS announces VPC encryption controls, a new capability that helps organizations audit and enforce encryption in transit for all traffic within and across VPCs in a Region, simplifying compliance with regulatory frameworks like HIPAA, PCI DSS, and FedRAMP through automated monitoring and enforcement modes. https://aws.amazon.com/ru/blogs/aws/introducing-vpc-encryption-controls-enforce-encryption-in-transit-within-and-across-vpcs-in-a-region/ (Use VPN to open from Russia) #aws