2068
All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops
🔶 boto3-refresh-session
A simple Python package for refreshing AWS temporary credentials in boto3 automatically
https://github.com/michaelthomasletts/boto3-refresh-session
#aws
Что загадывает DevOps на Новый год?
⏺чтобы кластер обновлялся без ночных алертов
⏺сеть работала стабильно и предсказуемо
⏺апгрейд кластера не превращался в вечер с release notes
Разработчики Managed Kubernetes в облаке MWS Cloud Platform ⬜ знают все ваши тайные желания и готовы упростить вашу DevOps-рутину.
С Managed Kubernetes вы получаете:
⏺готовый кластер за несколько минут без сложной настройки
⏺управление жизненным циклом кластера и нод
⏺ автоматическое масштабирование под нагрузку
⏺ нативную работу с сетью и storage через CCM / CSI
⏺ централизованное управление доступами через IAM
🔶🔷🔴 tokenex
A Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azure, OCI, Kubernetes, and OAuth2. You can also refer to the companion blog post.
https://github.com/riptideslabs/tokenex
#aws #azure #gcp
🔶 yams
A Go library, server, and CLI providing foundational capabilities to simulate access for AWS IAM policies.
https://github.com/nsiow/yams
#aws
🔶 AWS Builder Center
A portal collecting hands-on workshops crafted by AWS experts to gain practical experience and solve real business challenges.
https://builder.aws.com/build/workshops
(Use VPN to open from Russia)
#aws
🔶 All Paths Lead to Your Cloud: A Mapping of Initial Access Vectors to Your AWS Environment
Post which analyzes AWS initial access vectors through identity-driven misconfigurations, categorizing them into service exposure (Lambda, EC2, ECR, DataSync) and access by design (IAM/STS, IoT, Cognito) vulnerabilities that compromise cloud perimeter security.
https://www.paloaltonetworks.com/blog/cloud-security/aws-initial-access-cloud-perimeter-security/
(Use VPN to open from Russia)
#aws
👩💻 Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users
Datadog identified an active adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users. The campaign uses lookalike domains, proxies legitimate authentication pages, injects JavaScript to steal credentials and session tokens, and can bypass non-phishing-resistant MFA.
https://securitylabs.datadoghq.com/articles/investigating-an-aitm-phishing-campaign-m365-okta/
#azure
🔶 Amazon CloudWatch introduces unified data management and analytics for operations, security, and compliance
CloudWatch can automatically normalize and process data to offer consistency across sources with built-in support for Open Cybersecurity Schema Framework (OCSF) and Open Telemetry (OTel) formats, so you can focus on analytics and insights.
https://aws.amazon.com/ru/blogs/aws/amazon-cloudwatch-introduces-unified-data-management-and-analytics-for-operations-security-and-compliance/
(Use VPN to open from Russia)
#aws
🔶 Amazon CloudFront mTLS with open-source serverless CA
A step-by-step guide on implementing mTLS for Amazon CloudFront using our open-source cloud CA.
paulschwarzenberger/amazon-cloudfront-mtls-with-open-source-serverless-ca-f49ce2bc9874" rel="nofollow">https://medium.com/@paulschwarzenberger/amazon-cloudfront-mtls-with-open-source-serverless-ca-f49ce2bc9874
(Use VPN to open from Russia)
#aws
🔶 Introducing VPC encryption controls: Enforce encryption in transit within and across VPCs in a Region
AWS announces VPC encryption controls, a new capability that helps organizations audit and enforce encryption in transit for all traffic within and across VPCs in a Region, simplifying compliance with regulatory frameworks like HIPAA, PCI DSS, and FedRAMP through automated monitoring and enforcement modes.
https://aws.amazon.com/ru/blogs/aws/introducing-vpc-encryption-controls-enforce-encryption-in-transit-within-and-across-vpcs-in-a-region/
(Use VPN to open from Russia)
#aws
🔶 Introducing guidelines for network scanning
AWS introduces network scanning guidelines for customer workloads to distinguish legitimate security scans from malicious activity.
https://aws.amazon.com/ru/blogs/security/introducing-guidelines-for-network-scanning/
(Use VPN to open from Russia)
#aws
🔶 Simplify access to external services using AWS IAM Outbound Identity Federation
AWS IAM now enables outbound identity federation, allowing developers to securely authenticate AWS workloads with external services using short-lived JSON Web Tokens instead of storing long-term credentials like API keys and passwords.
https://aws.amazon.com/ru/blogs/aws/simplify-access-to-external-services-using-aws-iam-outbound-identity-federation/
(Use VPN to open from Russia)
#aws
👩💻 Terraform Stacks: A Deep-Dive for Azure Practitioners in Europe
This article explores Terraform Stacks for Azure on HCP Terraform EU. It covers designing stacks with components and deployments, building modules, configuring authentication via OIDC, passing data between stacks, and operational tasks like provisioning and managing stacks at scale.
https://mattias.engineer/blog/2025/terraform-stacks-deep-dive-azure/
#azure
🔶 Weaponizing the AWS CLI for Persistence
This article demonstrates weaponizing AWS CLI aliases for stealthy persistence. A one-liner dynamically toggles alias activation to execute malicious payloads while preserving original command functionality, evading detection. The technique exfiltrates credentials post-execution and persists across sessions, useful for red team operations.
https://slayer0x.github.io/awscli/
#aws
🔶🔷🔴 The log rings don’t lie: historical enumeration in plain sight
Logs aren't just for defenders. This research explores how attackers exploit cloud audit logs for enumeration and reconnaissance across AWS, Azure, and GCP, and how to detect and defend.
https://www.exaforce.com/blogs/log-rings-dont-lie-historical-enumeration-in-plain-sight
#aws #azure #gcp
👩💻 ATEAM
A Python reconnaissance tool designed to discover Azure services and attribute tenant ownership information based on their responses.
https://github.com/NetSPI/ATEAM
#azure
🔶 aws-extend-switch-roles
Extend your AWS IAM switching roles by Chrome extension, Firefox add-on, or Edge add-on.
https://github.com/tilfinltd/aws-extend-switch-roles
#aws
🔶 IAMhounddog
A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS accounts.
https://github.com/VirtueSecurity/IAMhounddog
#aws
🔶 aws-finops-dashboard
A terminal-based AWS cost and resource dashboard which provides an overview of AWS spend by account, service-level breakdowns, budget tracking, and EC2 instance summaries.
https://github.com/ravikiranvm/aws-finops-dashboard
#aws
🔶 AWS Lambda Managed Instances: A Security Overview
An initial security overview of AWS Lambda Managed Instances, exploring the Bottlerocket-based architecture, the 'Elevator' components, and security insights for this new compute model.
https://www.offensai.com/blog/aws-lambda-managed-instances-security-overview
(Use VPN to open from Russia)
#aws
🔶 Exploiting AWS IAM Eventual Consistency for Persistence
AWS IAM eventual consistency creates a 4-second window where deleted AWS access keys can still work. Learn how attackers exploit this and how to mitigate it.
https://www.offensai.com/blog/aws-iam-eventual-consistency-persistence
(Use VPN to open from Russia)
#aws
🔴 VPC Flow Logs for Cross-Cloud Network
With VPC Flow Logs, now you can monitor critical network traffic moving between your on-prem infrastructure, cross-cloud resources, and Google Cloud.
https://cloud.google.com/blog/products/networking/vpc-flow-logs-for-cross-cloud-network/
#gcp
🔶 Introducing AWS Lambda Managed Instances: Serverless simplicity with EC2 flexibility
Run Lambda functions on EC2 compute while maintaining serverless simplicity—enabling access to specialized hardware and cost optimizations through EC2 pricing models, with AWS handling all infrastructure management.
https://aws.amazon.com/ru/blogs/aws/introducing-aws-lambda-managed-instances-serverless-simplicity-with-ec2-flexibility/
(Use VPN to open from Russia)
#aws
👩💻 Backdooring Managed Identities via Azure API Management
Azure API Management exposes managed identity certificates with private keys in plaintext through an undocumented configuration API used by self-hosted gateways. Attackers with gateway keys can extract these certificates for persistent backdoor access.
https://dazesecurity.io/blog/apimMIVuln
(Use VPN to open from Russia)
#azure
🔶 AWS Secrets Manager launches Managed External Secrets for Third-Party Credentials
AWS Secrets Manager introduces managed external secrets for third-party credentials like Salesforce, Snowflake, and BigID.
https://aws.amazon.com/ru/blogs/security/aws-secrets-manager-launches-managed-external-secrets-for-third-party-credentials/
(Use VPN to open from Russia)
#aws
🔶 Phishing for AWS Credentials via the New ‘aws login’ Flow
The new aws login command, designed to provide temporary credentials for local development, can be exploited by attackers for phishing, even bypassing phishing-resistant MFA.
adan.alvarez/phishing-for-aws-credentials-via-the-new-aws-login-flow-39f6969b4eae" rel="nofollow">https://medium.com/@adan.alvarez/phishing-for-aws-credentials-via-the-new-aws-login-flow-39f6969b4eae
(Use VPN to open from Russia)
#aws
🔴 Introducing the Emerging Threats Center in Google Security Operations
Google introduces the Emerging Threats Center in Google Security Operations, powered by Gemini AI. It automates detection engineering by ingesting threat intelligence, generating synthetic events, testing coverage, and creating detection rules to help security teams rapidly assess exposure and defensive posture against emerging threats.
https://cloud.google.com/blog/products/identity-security/introducing-the-emerging-threats-center-in-google-security-operations/
#gcp
👩💻 Managing Privileged Roles in Microsoft Entra ID
A three-tier model for classifying privileged Microsoft Entra ID roles: Tier 0 (core tenant administration/security), Tier 1 (major service component administration), and Tier 2 (limited-scope/read-only). Each tier has defined security controls, addressing inconsistencies in Microsoft's privileged role documentation.
https://trustedsec.com/blog/managing-privileged-roles-in-microsoft-entra-id-a-pragmatic-approach
#azure
🔴 Private AI Compute: our next step in building private and helpful AI
Google introduces Private AI Compute, a cloud AI processing platform combining Gemini models with on-device-level privacy protections. It uses hardware-secured enclaves, remote attestation, and encryption to ensure personal data remains inaccessible to anyone, including Google, while enabling faster, more capable AI experiences.
https://blog.google/technology/ai/google-private-ai-compute/
#gcp
🔴 Hacking Gemini: A Multi-Layered Approach
The article describes exploiting multi-layered architecture discrepancies in Gemini to bypass Markdown sanitization. The researcher achieved image injection through linkification quirks and context bridges (Gemini-to-Colab), enabling workspace data exfiltration via indirect prompt injection despite existing protections.
https://buganizer.cc/hacking-gemini-a-multi-layered-approach-md
(Use VPN to open from Russia)
#gcp