CloudSec Wine
2.19K subscribers
973 photos
19 files
1.31K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
πŸ”Ά Spotted: How we discovered Privilege Escalation, missing CloudTrail data and a race condition in AWS Directory Service

A set of bugs in AWS Directory Service. One of them could be used for privilege escalation by an authenticated user with sufficient permissions.

https://cloudar.be/awsblog/spotted-privilege-escalation-in-aws-directory-service

#aws
πŸ”₯2πŸ‘1πŸ€”1
πŸ”Ά AWS Pentest Methodology

A high-level methodology of how one could conduct a penetration test inside the AWS platform.

https://medium.com/@MorattiSec/my-aws-pentest-methodology-14c333b7fb58

(use VPN to open from Russia)

#aws
❀4πŸ‘1πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”Ά Really cool illustration demonstrating some AWS services

🌍 Amazon CloudFront
🌐 Amazon Route 53
πŸ’» Amazon EC2
βš–οΈ Amazon Autoscaling
πŸͺͺ Amazon Certificate Manager
πŸͺ£ Amazon Backup service
πŸ—„οΈ Amazon RDS
☁️ Amazon VPC
πŸ” Amazon WAF
πŸ‘οΈ Amazon CloudWatch

https://www.linkedin.com/posts/nelsonamigoscode_aws-devops-awsdevops-activity-7076823493127884800-AN5_?utm_source=share&utm_medium=member_ios

(use VPN to open from Russia)

#aws
πŸ”₯4❀2πŸ‘1
πŸ”΄ Analyzing Volatile Memory on a Google Kubernetes Engine Node

Post explaining in detail how memory analysis works and how it can be used on any GKE node in production today.

https://engineering.atspotify.com/2023/06/analyzing-volatile-memory-on-a-google-kubernetes-engine-node

#gcp
πŸ‘4πŸ”₯2😱1
πŸ”Ά CloudGoat Vulnerable Lambda Scenario - Part 2 (Response)

As an incident responder, walk through how we can investigate and resolve an ongoing attack targeting CloudGoat's vulnerable Lambda scenario.

https://0xdeadbeefjerky.com/posts/cloudgoat-lambda-walkthrough-part-2

#aws
πŸ‘3❀1πŸ”₯1
πŸ”· nOAuth: How Microsoft OAuth Misconfiguration Can Lead to Full Account Takeover

An implementation flaw discovered in Microsoft Azure AD OAuth applications that, when exploited, could lead to full account takeover.

https://www.descope.com/blog/post/noauth

(use VPN to open from Russia)

#azure
πŸ‘2πŸ”₯2❀1
πŸ”Ά AWS CloudTrail cheat sheet

An attempt to document CloudTrail events that are "interesting" for incident responders or detection engineers.

https://invictus-ir.medium.com/aws-cloudtrail-cheat-sheet-dcf2b92e37e2

(use VPN to open from Russia)

#aws
πŸ‘4πŸ”₯1πŸ€”1
πŸ”Ά AWS announces Software Bill of Materials export capability in Amazon Inspector

Amazon Inspector now offers the ability to export a consolidated Software Bill of Materials (SBOMs) for all Amazon Inspector monitored resources across your organization in industry standard formats, including CycloneDx and SPDX.

https://aws.amazon.com/ru/about-aws/whats-new/2023/06/software-bill-materials-export-capability-amazon-inspector

#aws
πŸ”₯3πŸ‘2❀1
πŸ”Ά AWS WAF Clients Left Vulnerable to SQL Injection Due to Unorthodox MSSQL Design Choice

While doing research on Microsoft SQL (MSSQL) Server, a GoSecure ethical hacker found an unorthodox design choice that ultimately led to a web application firewall (WAF) bypass.

https://www.gosecure.net/blog/2023/06/21/aws-waf-clients-left-vulnerable-to-sql-injection-due-to-unorthodox-mssql-design-choice

#aws
πŸ‘3❀2πŸ”₯1
πŸ”Ά How to get rid of AWS access keys - Part 2: Reducing Privileges

How to reduce the privileges of AWS access keys in order to mitigate their risk.

https://www.wiz.io/blog/how-to-get-rid-of-aws-access-keys-part-2

#aws
πŸ‘3πŸ”₯3πŸ‘1
πŸ”ΆπŸ”·πŸ”΄ 8 Terraform continuous validation use cases for AWS, Google Cloud, and Azure

How to use Terraform "check" blocks and continuous validation with AWS, Google Cloud, and Azure services.

https://www.hashicorp.com/blog/8-terraform-continuous-validation-use-cases-for-aws-google-cloud-and-azure

#aws #azure #gcp
πŸ‘2πŸ”₯2❀1
πŸ”Ά Leveraging AWS SSO (aka Identity Center) with Google Workspaces

A Better way to configure AWS Identity Center to use Google Workspace/Cloud Identity with SCIM Support.

https://www.primeharbor.com/blog/aws-identity-center-google-v2

#aws
πŸ‘4πŸ”₯2😱1
πŸ”΄ How to migrate sensitive data with confidence using Google Cloud's CDMC-certified architecture

New and existing Google Cloud customers can migrate their sensitive data to the cloud with greater confidence thanks to the newly CDMC-certified architecture.

https://cloud.google.com/blog/products/identity-security/how-to-migrate-sensitive-data-using-google-clouds-cdmc-certified-architecture

#gcp
πŸ‘3πŸ”₯2😱1
πŸ”Ά Sometimes What Sounds Benign Can Bite You: An Unexpected Implication of Lambda Privileges

Granting a user the unconstrained permission to update Lambda function code in an AWS account can have unexpected, possibly severe, consequences under certain conditions that might not be obvious on first pass.

https://ermetic.com/blog/aws/sometimes-what-sounds-benign-can-bite-you-an-unexpected-implication-of-lambda-privileges

#aws
πŸ”₯3❀1πŸ‘1
πŸ”Ά Cedar: Avoiding the cracks

More and more engineers are considering integrating Cedar into their own systems for authorization, but what do policy authors need to consider to avoid unexpected outcomes?

https://onecloudplease.com/blog/cedar-avoiding-the-cracks

#aws
πŸ”₯2❀1πŸ‘1
πŸ”Ά What's New in AWS Certified Security Specialty SCS-C02 Exam in 2023?

The AWS Security Specialty Exam (SCS-C01) got a makeover and will be retiring next week. The new and improved SCS-C01, updated with new content and an added domain is now available.

https://twitter.com/4n6lady/status/1675636987133321217?s=46&t=J3j_Bp59pI4rfliKITPeZQ

(Use VPN to open from Russia)

#aws
πŸ‘3❀1πŸ”₯1
πŸ”΄ Configuring Workload Identity Federation for GitHub actions and Terraform Cloud

Workload Identity Federation can be integrated with external providers, such as Gitlab, GitHub actions and Terraform Cloud.

https://cloud.google.com/blog/products/identity-security/secure-your-use-of-third-party-tools-with-identity-federation

#gcp
πŸ‘2❀1πŸ”₯1
πŸ”· Public preview: Sensitive Data Protection for Application Gateway Web Application Firewall logs

Protect the sensitive data getting stored in your Web Application Firewall (WAF) logs using log scrubbing on Azure's regional Web Application Firewall running on Application Gateway.

https://azure.microsoft.com/en-us/updates/public-preview-sensitive-data-protection-for-application-gateway-web-application-firewall-logs

#azure
❀2πŸ‘2πŸ”₯1
πŸ”· Microsoft mitigates China-based threat actor Storm-0558 targeting of customer email

Microsoft has mitigated an attack by a China-based threat actor Microsoft tracks as Storm-0558 which targeted customer emails. Storm-0558 primarily targets government agencies in Western Europe and focuses on espionage, data theft, and credential access.

https://msrc.microsoft.com/blog/2023/07/microsoft-mitigates-china-based-threat-actor-storm-0558-targeting-of-customer-email/

#azure
❀2πŸ‘2πŸ”₯1
πŸ”Ά Refining IAM Permissions Like A Pro

How to detect unused IAM permissions and update them to move safely toward a least privilege environment.

https://catalog.workshops.aws/refining-iam-permissions-like-a-pro/en-US

#aws
πŸ‘3❀1πŸ”₯1