home.social

#awssecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #awssecurity, aggregated by home.social.

  1. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  2. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  3. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  4. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  5. Some early morning coffee and catching up on the latest AWS IAM news and blogs on my Kindle Scribe - love this big screen! Becoming a bit of a habit (a good one too). #aws #awssecurity

  6. We ask #ChatGPT about an oft overlooked policy that you should be putting in place when using #VPC #Endpoints in #AWS. Do NOT inadvertently allow access to other tenants' resources!

    FOLLOW US as we explore cloud network security with #AI.

    #awssecurity

  7. TIL, there's a hard coded client_id in the #AWS #awsconsole for what I suspect is an AWS managed account that handles oauth2.0 for root/some login types.

    The client_id depending on the service that it first redirects looks like this arn:aws:iam:015428540659:user/s3

    Another service that I've noticed is phd-console (Which I think is AWS health dashboard).

    So in this pattern it looks like your secret access key is treated as the client secret in an authorization code flow.

    The code/access token returned by AWS is an opaque encrypted JWT.

    #awssecurity

  8. 🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.

    youtube.com/watch?v=H7C-qUZm8m

    #AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource

  9. The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! aws.amazon.com/blogs/security/ #awssecurity #awscloud

  10. #ChatGPT explaining cross-account Security Group referencing pretty neatly. One of the easiest ways to implement an IP Address-free trust between connected apps in #AWS.

    Also called #microsegmentation.

    FOLLOW US as we explore cloud network security with #AI.

    #awssecurity

  11. #ChatGPT may have passed law and business exams, but it won't be getting #AWS networking certifications anytime soon.

    9.9.9.9 is not in the 128.0.0.0/1 subnet, and Rules are not evaluated sequentially 🤦

    FOLLOW US as we explore cloud networking security with #AI!

    #awssecurity

  12. Had to put words in #ChatGPT's mouth to get this answer.

    Does anybody know if calls to the time sync service are logged? Maybe that's what we'll ask in a couple of days.

    FOLLOW US as we talk to #AI about cloud network security.

    #awssecurity

  13. Best to configure Route53 Resolver Firewall so exfil can only happen to trusted parties 😅

    #awssecurity

    infosec.exchange/@ChaserSystem