tgindex

CloudSec Wine

описание

All about cloud security Contacts: @AMark0f @dvyakimov About DevSecOps: @sec_devops

2 259
подписчиков
Охват к подписчикам
12,7%
ERR
Реакции к просмотрам
0,83%
155 на 49 постов
Пересылки к просмотрам
1,02%
191
Постов в день
0,6
всего 55

Где отзываются чаще

доля реакций к просмотрам
  • 14 авг.🔶 HIPAA Security Rule on AWS AWS released a whitepaper guiding covered entities and business associates on implementing HIPAA Security Rule Technical Safeguards on AWS, covering access control, audit, MFA, encryption, and 2025 NPRM proposed changes, with shared responsibility mapping and ePHI architecture guidance. https://aws.amazon.com/ru/blogs/security/hipaa-security-rule-on-aws-technical-safeguards-implementation-and-readiness-guidance #aws3,57%
  • 13 авг.🔴 Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline Google Cloud CISO Chris Betz argues that AI-native threat defense is now a board-level requirement. Boards should govern five areas: business enablement, remediation cycle speed, platform consolidation, contextual vulnerability prioritization, and AI safety policy to enable secure, AI-driven business agility. https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-why-ai-threat-defense-is-the-new-boardroom-baseline #gcp1,80%
  • 12 авг.👩‍💻 CosmosEscape: Taking Over Every Azure Cosmos DB Wiz Research found CosmosEscape, a critical vulnerability in Azure Cosmos DB's Gremlin API enabling sandbox escape via .NET reflection. Attackers could obtain a platform-wide Cosmos Master Key granting full read/write access to any customer database and enumeration of all accounts. https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db #azure1,56%
  • 3 авг.🤖 Inside the OpenClaw Ecosystem: What Happens When AI Agents Get Credentials to Everything Permiso researchers deployed an AI agent (Rufio) into the OpenClaw ecosystem and found active malware campaigns in its unvetted skill marketplace (ClawHub), credential-harvesting skills with 377+ downloads, C2 infrastructure, and prompt injection attacks targeting agents holding plaintext credentials to email, Slack, and file systems. https://permiso.io/blog/inside-the-openclaw-ecosystem-ai-agents-with-privileged-credentials #AI1,50%
  • 5 авг.🤖 Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to HunggingFace's incident disclosure from last week. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how they investigated with GLM 5.2. https://huggingface.co/blog/agent-intrusion-technical-timeline #AI1,42%
  • 11 авг.🤖 Before the first prompt: Code execution paths in trusted coding-agent projects Trusted coding-agent projects can execute repository-controlled code before the first user prompt via MCP server configs or PATH hijacking in .claude/settings.json. Developers should treat project trust like running an arbitrary setup script. https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt #AI1,27%
  • 22 маябез подписи1,24%
  • 10 авг.🔶 Investigating Persistence Mechanisms in AWS Rapid7 Labs details four AWS persistence techniques used by attackers: rogue IAM user creation, backdoored assume role policies granting external account access, malicious Lambda functions provisioning privileged users, and federated user sessions that survive key rotation. Includes LEQL detection queries and remediation steps. https://www.rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms #aws1,22%
  • 29 июл.🤖 Delegated authority, running locally: Give an agent on your machine an identity you can trust A reference architecture for giving a locally-running AI agent a trustworthy, auditable identity, without long-lived credentials on disk, including a structural defense against prompt injection built into the protocol layer. https://1password.com/blog/ai-agent-identity-delegated-local #AI1,20%
  • 14 янв.без подписи1,12%
  • 17 июн.без подписи1,11%
  • 4 авг.🤖 Least privilege for AI agents: Identity, access, and tool binding AI agents acting as autonomous multi-system actors require dedicated managed identities, least-privilege task-scoped RBAC, explicit tool allowlists, JIT time-limited entitlements, downstream re-authorization per call, and end-to-end audit logs capturing identity, role, scope, and correlation IDs. https://www.microsoft.com/en-us/security/blog/2026/07/16/least-privilege-for-ai-agents-identity-access-and-tool-binding #AI1,10%