CloudSec Wine
2.26K subscribers
1.09K photos
24 files
1.4K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
🔶 Global S3: Another C2 Channel for AgentCore Code Interpreters

AWS AgentCore Code Interpreters in Sandbox mode allow unrestricted global S3 access (including cross-account, public/presigned URLs), enabling a bidirectional C2 channel via S3 polling, demonstrated as a full reverse shell PoC. Mitigation: use VPC mode with S3 Gateway Endpoints and strict endpoint policies.

https://sonraisecurity.com/blog/global-s3-another-c2-channel-for-agentcore-code-interpreters

#aws
2👍1🔥1
🌩 When Background AI Agents Become a Security Boundary Problem

Claude Code's background sessions, supervisor process, CLAUDE_CONFIG_DIR override, scheduled tasks, and Markdown-based agent definitions can be chained post-foothold to deploy a persistent, nearly invisible C2 agent evading standard EDR binary-focused detection.

https://www.originhq.com/research/background-c2-agent

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🔴 Securing Your Gemini and Google API Keys

Protect your Gemini API keys with this guide on API restrictions, secure storage in Secret Manager, and key hygiene to prevent hijacking and unauthorized use.

https://cloud.google.com/blog/topics/developers-practitioners/api-keys-are-open-secrets

#gcp
2👍1🔥1
🤖 Comparing AI Application Security Testing Platforms

Doyensec compared Aikido Attack AI Pentest and XBOW Lightspeed for web app vulnerability detection, evaluating true/false positives, configuration, report quality, cost, speed, and impact on tested applications. Full findings available as a PDF.

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🤖 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents

A guide to understanding Copilot Studio AI agents, their deeper architecture on Entra ID and APIM, and key security risks.

https://www.beyondtrust.com/blog/entry/copilot-studio-ai-agents-security-risks

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🔶 Well-architected best practices for software supply chain security

Aligned with the AWS Well-Architected Security Pillar, the article recommends defending against npm supply chain attacks (e.g., Shai-Hulud) by using temporary credentials, least-privilege IAM, artifact signing via AWS Signer, centralized dependency management with CodeArtifact, continuous scanning via Amazon Inspector, and CloudTrail-based monitoring.

https://aws.amazon.com/ru/blogs/security/well-architected-best-practices-for-software-supply-chain-security

#aws
👍32🔥1
🤖 ChatGPhish: The Page Is the Payload

Any web page a victim asks ChatGPT to summarize can become a phishing payload. P0 Labs research reveals a Markdown rendering vulnerability in ChatGPT's response UI.

https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
👩‍💻 Azure’s Hidden Operators: A Threat Model for Platform-Level Managed Identities

Post which explores, names, defines, and threat-models an Azure identity type that has quietly operated inside every customer tenant. Never documented under a single name, never owned by you, and never fully visible to you.

https://www.vectra.ai/blog/azures-hidden-operators-a-threat-model-for-platform-level-managed-identities

#azure
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1
🤖 Hermes-USB-Portable

Run a fully self-contained, self-improving AI agent from a single folder or USB drive.

https://github.com/techjarves/hermes-usb-portable

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
👍21🔥1
🌩 Hidden Gaps in Claude Code Security Reviews

Claude Code's /security-review is vulnerable to model anchoring bias when run in the same session that wrote the code. A new diff-scoped plugin avoids this but misses cross-commit vulnerability chains where each individual change appears benign in isolation.

https://brainoverflow.blog/posts/claude-code-security-review-bias

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
👍41🔥1
🔐 Identity and Access Management Whitepaper

CNCF TAG Security released an IAM whitepaper targeting architects and platform engineers, covering zero-trust vs. perimeter models, PEP/PDP-based authorization, SPIFFE workload identity, and authentication patterns for stateful and stateless cloud native workloads.

https://www.cncf.io/blog/2026/06/04/identity-and-access-management-whitepaper

#iam
Please open Telegram to view this post
VIEW IN TELEGRAM
2👍2🔥1
Identity-and-Access-Management-Whitepaper.pdf
814.6 KB
👍41🔥1
🔶 Operationalizing AWS security: A maturity roadmap

A six-phase maturity roadmap for operationalizing AWS Security Hub and GuardDuty: assess current state, reduce alert noise via tuning, build tiered notification routing, implement automated remediation for high-confidence findings, establish recurring review cadences with metrics, then expand with Inspector, Macie, Security Lake, and preventive controls.

https://aws.amazon.com/ru/blogs/security/operationalizing-aws-security-a-maturity-roadmap

#aws
1👍1🔥1
🌩 Securing CI/CD in an agentic world: Claude Code Github action case

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows.

https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case

#ClaudeCode
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍31🔥1
🤖 Entra Agent ID: The blueprint blast radius

Entra Agent ID is an extension of Entra's application model that provides identities for AI agents. Unlike applications, the agent identity model allows linking a single app registration (blueprint) to multiple identities and their associated privileges, increasing the potential blast radius of a compromised agent.

https://securitylabs.datadoghq.com/articles/agent-id-blueprint-blast-radius

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
1👍1🔥1