CloudSec Wine
2.25K subscribers
1.08K photos
24 files
1.39K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
👨‍💻 Widespread GitHub Campaign Uses Fake VS Code Security Alerts to Deliver Malware

A large-scale phishing campaign is targeting developers directly inside GitHub, using fake Visual Studio Code security alerts posted through Discussions to trick users into installing malicious software.

https://socket.dev/blog/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware

#github
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
📤 Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure

Railway PaaS is being weaponized as a clean token replay engine in an active AiTM and device code phishing campaign impacting 268+ M365 organizations and 100+ MSPs.

https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign

#PaaS
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍1🔥1
🔴 Double Agents: Exposing Security Blind Spots in GCP Vertex AI

Unit 42 researchers found that GCP Vertex AI Agent Engine's default P4SA service account has excessive permissions, enabling credential theft via the metadata service. This allows privilege escalation to read all consumer GCS buckets, access restricted Google-internal Artifact Registry container images, and expose internal source code.

https://unit42.paloaltonetworks.com/double-agents-vertex-ai

#gcp
1👍1🔥1
🔶 Enforcing AI Governance Across AWS Organizations

Learn how to enforce AI governance across AWS organizations using Bedrock guardrails, MCP server controls, model availability rules, and API restrictions to reduce risk and improve security.

https://sonraisecurity.com/enforcing-ai-governance-across-aws-orgs

#aws
2👍1🔥1
🔶 aws-preflight

Check your AWS CLI commands for security risks before you run them.

https://github.com/gabrielPav/aws-preflight

#aws
1👍1🔥1
🔶 AWS Security Agent on-demand penetration testing now generally available

AWS Security Agent on-demand penetration testing is now GA, offering autonomous 24/7 multi-cloud pen testing combining SAST, DAST, and context-aware agentic AI.

https://aws.amazon.com/ru/blogs/security/aws-security-agent-on-demand-penetration-testing-now-generally-available/

#aws
🔥41👍1
🤖 How Command Injection Vulnerability in OpenAI Codex Leads to GitHub Token Compromise

BeyondTrust Phantom Labs recently identified a critical command injection vulnerability in OpenAI Codex that allowed for the theft of GitHub User Access Tokens.

https://www.beyondtrust.com/blog/entry/openai-codex-command-injection-vulnerability-github-token

#AI
1👍1🔥1
🔶 Unexpected Routing Behaviour in AWS with VPC Peering and NAT Gateway

When routing VPC peering traffic through an internal NAT gateway in AWS, response traffic bypasses route tables via connection tracking, making all subnets in the peered VPC reachable even without return routes configured. AWS confirmed this is "expected behaviour.".

https://labs.reversec.com/posts/2026/03/unexpected-routing-behaviour-in-aws-with-vpc-peering-and-nat-gateway

#aws
1👍1🔥1
🔶 Launching S3 Files, making S3 buckets accessible as file system

Amazon S3 Files makes S3 buckets accessible as high-performance file systems on AWS compute resources, eliminating the tradeoff between object storage benefits and interactive file capabilities while enabling seamless data sharing with ~1ms latencies.

https://aws.amazon.com/ru/blogs/aws/launching-s3-files-making-s3-buckets-accessible-as-file-systems

#aws
1👍1🔥1
🔶 Amazon S3 starts rolling out new security best practice to new and existing buckets by default

S3 is now deploying a new default bucket security setting which will automatically disable server-side encryption with customer-provided keys (SSE-C) for all new general purpose buckets.

https://aws.amazon.com/ru/about-aws/whats-new/2026/04/s3-default-bucket-security-setting

#aws
1👍1🔥1
🤖 NomShub: Weaponizing Cursor's Remote Tunnel Through Indirect Prompt Injection and Sandbox Breakout

NomShub is a critical vulnerability chain in the Cursor AI code editor where a malicious repository can silently hijack a developer's machine, combining indirect prompt injection, a sandbox escape via shell builtins, and Cursor's built-in remote tunnel to give attackers persistent, undetected shell access triggered simply by opening a repo.

https://www.straiker.ai/blog/nomshub-cursor-remote-tunneling-sandbox-breakout

#AI
1👍1🔥1
🤖 Claude & Control: An Introduction to Agentic C2 with Computer Use Agents

This blog explores how computer use agents can be used to build an agentic command-and-control framework. By combining LLM reasoning with desktop interaction tools, attackers could automate endpoint control while blending into normal system behavior. Here, we break down the architecture, abuse scenarios, and detection opportunities.

https://www.beyondtrust.com/blog/entry/claude-control-agentic-c2-computer-use-agent

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🔶 A framework for securely collecting forensic artifacts into S3 buckets

Blog presenting an AWS architecture for securely collecting forensic artifacts into S3, using IAM least-privilege session policies, STS time-limited credentials scoped per case prefix, KMS encryption, S3 versioning, and an automated Step Functions/Lambda/SSM workflow deployable via AWS CDK.

https://aws.amazon.com/ru/blogs/security/a-framework-for-securely-collecting-forensic-artifacts-into-s3-buckets

#aws
🔥21👍1
🤖 The “AI Vulnerability Storm”: Building a “Mythos-ready” Security Program

AI, as demonstrated by Anthropic's Mythos, has significantly increased the likelihood of attackers discovering new vulnerabilities, creating new exploits, and using them in complex automated attacks at scale. While AI also increases the speed of patch development and reduces defects in new software, defenders still face a heavier relative burden due to the inherent limitations of patching. Attackers gain asymmetric benefits.

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1