This week's articles
Getting into AWS cloud security research
#strategy
How to start doing AWS security research. What you need to learn, who you should learn from, and what you should think about along the way while not actually doing research.
Authorizing cross-account KMS access with aliases
#aws, #build
KMS aliases are a great way to make KMS keys more convenient. But permitting one account to use an KMS key in another account through a KMS alias can be difficult. This article explains why, and how to solve the problem correctly.
Falco-bypasses
#attack, #falco
Research on various techniques to bypass default falco ruleset.
5 Tips to prevent or limit the impact of an incident in Azure
#azure, #defend
Five low-cost and easy to implement measures with high-impact to prevent or limit the impact of an incident in Azure: setup budget quotas, restrict app registration, prevent subscriptions from entering your tenant, ingest audit logging, and limit external collaboration.
|
|
Tools
cedar-flask-demo
A demo to show how you can use Cedar in Python, with a simple Flask based web application.
XMGoat
Terraform templates that help you learn about common Azure security issues. Each template is a vulnerable environment, with some significant misconfigurations.
power-pwn
An offensive and defensive security toolset for Microsoft 365 Power Platform.
k8s-network-policy-migrator
K8s Network Policy Migrator is a tool to migrate Calico or Cilium custom network policies to Kubernetes native network policy.
|
|
Sponsor
Applying the Principles of Zero Trust to SSH Zero Trust security strategies are essential for managing the security threats of today's complex, highly distributed infrastructures. In this brief article, learn how you can securely access resources in cloud-native, hybrid cloud, or legacy environments without broad, static rights using the right tools. This should also facilitate access and keep the user experience the same or make it better.
|
|
|
Jobs
Hiring? Feature your listings below - reach out now at [email protected]
|
|
|
Principal DevSecOps Engineer - Accenture Federal Services
AFS is seeking a Principal DevSecOps Engineer to be responsible for building and setting up new development tools and infrastructure utilizing knowledge in continuous integration, delivery, and deployment (CI/CD), Cloud technologies, Container Orchestration and Security.
Cloud Security Engineer - Rackspace
Rackspace Cyber Defence is looking for an Indian based Security Engineer, with a specialism in Cloud Security to support Rackspace's strategic customers.
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌 If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|