This week's articles
Announcing the EKS Cluster Games
#attack, #aws, #explain, #kubernetes
Wiz released "The EKS Cluster Games", a cloud security Capture The Flag (CTF) event. The mission? To identify and learn about common Amazon EKS security issues.
The deputy is confused about AWS Security Hub
#aws, #build, #explain
The article highlights a potential issue with AWS Security Hub where incorrect AWS account IDs could lead to cross-tenant data pollution, potentially allowing an attacker to pollute someone else's Security Hub.
|
|
Tools
localtoast
Localtoast is a scanner for running security-related configuration checks such as CIS benchmarks in an easily configurable manner.
GOAD
GOAD is a pentest active directory LAB project. The purpose of this lab is to give pentesters a vulnerable Active directory environment ready to use to practice usual attack techniques.
cuddlephish
Weaponized Browser-in-the-Middle (BitM) for Penetration Testers.
|
|
Sponsor
O'Reilly: Identity-Based Infrastructure Access Management Identity-Native Infrastructure Access is the concept of linking access to an identity. Instead of sharing passwords or other secrets, access is granted on an individual's identity. Deployed by the world's largest tech companies, it's the only way to securely scale access. So, how can you secure access to diverse infrastructure components, from bare metal to ephemeral containers, consistently and simply? In this practical book, authors Ev Kontsevoy, Sakshyam Shah, and Peter Conrad break this topic into manageable pieces.
|
|
|
From the cloud providers
Forward access sessions
Learn about passing your identity, permissions, and session attributes when an AWS service makes a request on your behalf.
|
|
Sponsor CloudSecList
If you want to get your product or job ad in front of thousands of security professionals, ranging from engineers to CISOs and VCs, at companies ranging from small start-ups to Fortune500 and FAANG, you can reach out at 📨 [email protected] 📨
|
|
|
Business News
-
Cloud Security: factors that make it a unique market (source)
-
Confirmed: Palo Alto Networks buys Dig Security, sources say for $400M (source)
-
No Way Out: The Changing World of Cybersecurity Exits (source)
-
Microsoft launches internal initiative to make its products more secure (source)
-
Cloudflare Announces Third Quarter 2023 Financial Results (source)
-
Chainguard secures $61m for open source software security boost (source)
-
Atlassian urges customers to take 'immediate action' to protect against data-loss security bug (source)
-
Cyber consolidation: SailPoint closes Osirium acquisition as Proofpoint to buy Tessian (source)
-
P0 Security Raises $5M in Seed Funding (source)
-
Orca Security Announces Generative AI Integration With Amazon Bedrock (source)
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌 If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|