home.social

#cloudsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cloudsec, aggregated by home.social.

fetched live
  1. 🤖 Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

    📝 AI models have reached a threshold ...

    microsoft.com/en-us/security/b

    📰 Microsoft Security Blog

    #AI #CloudSec #CVE

  2. 🏛️ CISA Contractor AWS GovCloud Security Leak

    📝 CISA contractor exposed AWS GovCloud credentials and internal system details.

    schneier.com/blog/archives/202

    📰 Schneier on Security

    #GovSec #AI #CloudSec

  3. 🚩 CoPhish phishing campaign (HIGH severity) targets Copilot Studio agents to steal OAuth tokens — enabling session hijack & cloud access. No CVE. User training, OAuth app reviews, and token monitoring are key. Details: radar.offseq.com/threat/new-co #OffSeq #OAuth #Phishing #CloudSec

  4. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Cloud Native Security; Explained”
    📽️ twp.ai/4ipSVP

    #CyberSecurity #SecurityAwareness #cloudsec #cloud #cloudnative

  5. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Cloud Native Security; Explained”
    📽️ twp.ai/4iosID

    #CyberSecurity #SecurityAwareness #cloudsec #cloud #cloudnative

  6. 🎥 Missed one of my past conference talks? Let’s fix that.

    I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

    “Cloud Native Security; Explained”
    📽️ twp.ai/4in9re

    #CyberSecurity #SecurityAwareness #cloudsec #cloud #cloudnative

  7. 🔐 Gamma AI is now being used to craft pixel-perfect phishing pages.
    These attacks mimic cloud login portals, flip JavaScript behavior, and bypass email filters.

    📉 We break it all down in our latest article:
    — Real misuse cases
    — MITRE TTP matrix
    — Python detection script
    — Visual trust infographic

    📖 Read it here: open.substack.com/pub/teamivit

    #CyberSecurity #GammaAI #LLMSecurity #CloudSec #Phishing #Infosec

  8. Hot take, If you develop for cloud environments you need to get used to a default deny on egress and only allow dependencies to be pulled during the build phase. You should know exactly what is talking to where and why. allow all on egress is the equivalent to I chmod 777'd it and it works so whatever...

    #cloudsecurity #CloudSec #HotTake #Infosec

  9. "An open-source collection of cloud infrastructure best practices, for bootstrapping your own cloud platform."

    cloudguardrails.com/

    #security #cybersecurity #cloud #cloudsec

  10. Day 1 of #BlackHatUSA2024

    I am around the BlackHat area connecting with old friends and making new friends.

    feel free to connect, highly interested in discussions around mobile, cloud, and supply chain security.

    #infosec #mobilesec #cloudsec # #blackhat

  11. The Loco Moco Security Conference (LocoMocoSec) #cfp is open until March 21st. The event takes place July 17th and 18th in Līhuʻe on Kauaʻi, Hawaiʻi sessionize.com/loco-moco-secur #appsec #prodsec #cloudsec

  12. To me, it feels like organizations with a dedicated Security team that are developer and IDAM-led are "modern" and "best-of-breed." When you talk to these teams and individuals you feel encouraged and empowered. It feels like you're living and working in 2024. These teams know #CloudSec, #AppSec, and have the technical chops to address myriad InfoSec challenges. They seem to harness all sorts of technical ways and means like automation and AI. I know these organizations make me feel hopeful (which is damn near impossible).

    On the flip side though, there are still countless Security organizations (especially in the reseller and VAR space) being "led" by the Network folks. What I find most interesting is these Cisco-centric individuals/teams have almost no way to even relate to the best-of-breed model I called out above. Talking to these folks feels like you're in a time capsule and the year is 2011.

    I can't help but wonder if this is just my experience or if others are seeing and feeling this as well.

    #Infosec #informationsecurity

  13. Major cloud hosting provider LeaseWeb is working to restore "critical" systems after a security breach caused the company to take the affected systems offline to mitigate security risks.

    In its statement, it told customers that only a small percentage of their cloud customers were impacted by the downtime. The company goes on to say that they have retained a Digital Forensics & Incident Response (DFIR) firm to assist with its investigation.

    https://www.bleepingcomputer.com/news/security/leaseweb-is-restoring-critical-systems-after-security-breach/

    #infosec #cybersecurity #securitybreach #Leaseweb #CloudSec

  14. 🔎 findmytakeover

    Scans AWS, Azure, and Google Cloud for dangling DNS records and potential subdomain takeovers

    #CloudSec #cybersecurity

  15. Headed to the #cloudsec superb owl

    If you make it to Anaheim, say hi 👋

  16. We need to talk about cloud security automation. The room for improvement is huge and the current state is really painful.

    If you're running a Large Cloud Infrastructure, I want to hear from you! What are your challenges? Your solutions?

    ldse.substack.com/p/about-clou

    #cloudsec #automation #securityautomation