CloudSec Wine – Telegram
CloudSec Wine
2.14K subscribers
917 photos
18 files
1.26K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
🔶 Determining AWS IAM Policies According To Terraform And AWS CLI

The process of granting the least privileges required to execute "aws s3 ls" and "terraform apply" by a CI/CD runner.

https://www.iampulse.com/t/determining-aws-iam-policies-according-to-terraform-and-aws-cli

#aws
🔶 Running AWS PCI DSS with CloudQuery Policies

CloudQuery policies gives you a powerful way to automate, customize, codify, and run your cloud security & compliance continuously with HCL and SQL. CloudQuery’s Yevgeny Pats describes their new AWS PCI DSS Policy, containing over 40 checks.

https://www.cloudquery.io/blog/running-aws-pci-dss-with-cloudquery-policies

#aws
🔶 Achieving Least Privilege with AWS IAM

Anthony Barbieri shares a few tips and tricks on the authorization side of IAM. Topics: client side monitoring and Cloudtrail, understanding which actions support resources restrictions, policy management, and leveraging conditions.

https://dev.to/prince_of_pasta/achieving-least-privilege-with-aws-iam-10i

#aws
🙂 Dear friends,
Happy New Year 2022! 🎅

We wish you personal and career success. Stay with us. Next year we will continue to delight you with only high-quality content!

#HappyNewYear
🔷 NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories

Another vulnerability discovered by the Wiz Research Team, where the Azure App Service exposed hundreds of source code repositories.

https://blog.wiz.io/azure-app-service-source-code-leak/

#azure
🔴 Cloud-Native Ransomware Protection in GCP

The five pillars of the NIST CSF help create a layered security approach to the fight against ransomware.

https://scalesec.com/blog/cloud-native-ransomware-protection-gcp/

#gcp
🔶 Get Email Notification On AWS IAM User Creation

Example CloudWatch rule and Lambda function to send an email via SES whenever an IAM user is created.

https://www.iampulse.com/t/get-email-notification-on-aws-iam-user-creation

#aws
🔴 Impersonate the Cloud: Running your app locally as if you were on Google Cloud

Some ways to securely run an app locally with the exact same context as on Google Cloud.

https://www.iampulse.com/t/impersonate-the-cloud-running-your-app-locally-as-if-you-were-on-google-cloud

#gcp
🔶 2 Critical Cloud Vulnerabilities to Convince You to Move to the Cloud

The Orca Security Research Team wrote about 2 critical zero-day vulnerabilities affecting AWS: Superglue and BreakingFormation. These vulnerabilities could've allowed unauthorized access to customer data and/or sensitive code and data within AWS.

https://orca.security/resources/blog/two-critical-cloud-vulnerabilities/

#aws
🔷 Persistence with Azure Policy Guest Configuration

Use Azure Policy Guest Configuration to gain persistence in your target environment and how to detect such an attack as a defender.

https://cloudbrothers.info/en/azure-persistence-azure-policy-guest-configuration/

#azure
🔴 Geofencing a Globally Load Balanced service on GCP using Cloud Armor

How to use Cloud Armor to geofence a website/service running on GCP using Cloud Run, Google Cloud Storage (GCS) and the Global HTTP(S) Load Balancer.

https://medium.com/google-cloud/geofencing-a-globally-load-balanced-service-on-gcp-using-cloud-armor-44099480fd00

#gcp
🔶 Vulnerable AWS Lambda function - Initial access in cloud attacks

How a vulnerable AWS Lambda function could be used by attackers, and some best practices to mitigate these attacks.

https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/

#aws
🔴 Creating your first GCP Organization

A walk-through for anyone who hasn't yet created their first Google Identity domain for experimentation in GCP.

https://www.chrisfarris.com/post/gcp-create-domain/

#gcp