CloudSec Wine
2.27K subscribers
1.13K photos
24 files
1.43K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
🔶 Apps can now impersonate human access to AWS via IAM Identity Center

AWS IAM Identity Center now lets server-side apps exchange an IdP-issued OIDC token for user-scoped AWS credentials via CreateTokenWithIAM, ListAccounts, and GetRoleCredentials. Actions are attributed to the user in CloudTrail. Key gaps: no per-app scope restrictions and no application ARN in audit trails.

https://awsteele.com/blog/2026/07/01/apps-can-now-impersonate-human-access-to-aws-via-iam-identity-center.html

#aws
❤1👍1🔥1
🔶 whim

Throwaway root shells in AWS Lambda Firecracker microVMs.

https://github.com/udgover/whim

#aws
❤1👍1🔥1
🔶 Introducing OAuth Support for AWS MCP Server

AWS MCP Server now supports OAuth-based sign-in using existing AWS credentials (IAM, IAM Identity Center, federated). Includes dynamic client registration, headless token API, new IAM condition keys, token introspection/revocation, and CloudTrail logging for OAuth events.

https://aws.amazon.com/ru/blogs/security/introducing-oauth-support-for-aws-mcp-server

#aws
❤1👍1🔥1
🔶 Authenticate legitimate AI agent traffic with AWS WAF Bot Control

AWS WAF Bot Control now supports Web Bot Authentication (WBA), using ed25519 cryptographic signatures (RFC 9421) to verify AI agent identities. It introduces new WAF labels (verified, invalid, expired, unknown_bot) enabling granular allow/block rules, replacing unreliable IP-based bot filtering.

https://aws.amazon.com/ru/blogs/security/authenticate-legitimate-ai-agent-traffic-with-aws-waf-bot-control

#aws
❤3👍1🔥1
🔶 OIDC tokens can now restrict which AWS roles they assume

AWS STS now supports a new OIDC claim that restricts which role ARNs a token can assume. Enforced before trust policy evaluation. The boolean condition key sts:RoleAuthorizedByIdp enables mandatory enforcement via trust policies or RCPs.

https://awsteele.com/blog/2026/07/13/oidc-tokens-can-restrict-which-aws-roles-they-assume.html

#aws
❤2👍1🔥1
🔶🔷🔴 The Two Mitigations for the Service-Account Confused Deputy in the Cloud

Two mitigations exist for cloud service-account confused deputy attacks: for customer-managed identities, an attachment gate (GCP actAs, AWS iam:PassRole, Azure assign/action) controls bind-time authorization; for provider-managed identities, the CSP enforces internal checks, with AWS uniquely exposing this via Forward Access Sessions and condition keys.

https://kattraxler.cloud/the-two-mitigations-for-the-service-account-confused-deputy-in-the-cloud

#aws #azure #gcp
❤1👍1🔥1
🔶 Introducing Claude apps gateway for AWS

Amazon announced the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop.

https://aws.amazon.com/ru/blogs/machine-learning/introducing-claude-apps-gateway-for-aws

#aws
❤1👍1🔥1
🔶 Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment

Amazon GuardDuty investigation agent (public preview) uses AI to auto-investigate GuardDuty security findings, reducing investigation time from hours to minutes. It returns risk levels, confidence scores, MITRE ATT&CK mappings, and remediation steps via console, CLI, API, or AWS MCP server.

https://aws.amazon.com/ru/blogs/security/introducing-the-amazon-guardduty-investigation-agent-on-demand-ai-powered-threat-assessment

#aws
❤1👍1🔥1
🔶 Investigating Persistence Mechanisms in AWS

Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps.

https://www.rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms

#aws
❤1👍1🔥1
🔶 HIPAA Security Rule on AWS

AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance.

https://aws.amazon.com/ru/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance

#aws
❤2👍1🔥1