This week's articles
Terraform Security Best Practices
#build, #defend, #terraform
Post providing guidance for using Terraform in a secure way by reference to some security best practices around auditing Terraform configurations, managing access credentials, and creating DIY Terraform modules.
The Triforce of Initial Access
#attack, #azure, #saas
The article emphasizes that the success of Red Teaming often hinges on the quality of information (loot) gathered and the effectiveness of the tools used, such as Evilginx, ROADtools, and TeamFiltration, complemented by the Bobber script.
Secure Application Communications with Mutual TLS and Istio
#explain, #istio, #kubernetes
Post discussing the requirements of secure communication among applications, how mTLS enables and meets all those requirements, along with simple steps to get you started with enabling mTLS among your applications using Istio.
|
|
Tools
kube-audit-rest
Kubernetes audit logging, when you don't control the control plane.
FARA
Repository that contains a set of purposefully erroneous Yara rules. It is meant as a training vehicle for new security analysts, those that are new to Yara and even Yara veterans that want to keep their rule writing (and debugging) sharp.
aws-ml-opt-out
A Terraform module that makes it a snap to opt out of all AWS AI/ML data harvesting.
MTKPI
Multi Tool Kubernetes Pentest Image.
|
|
CloudSecDocs
Activate GCP
Step-by-step instructions (with screenshots) for activating GCP in a Google Workspace account.
|
|
Sponsor
Give Your GRC Some TLC Simplify your security and manage compliance 80% faster with automated evidence collection and control monitoring. See why 3,200+ customers choose Drata to automate compliance for SOC 2, ISO 27001, GDPR, and 14 other frameworks with none of the manual work. That’s right—no screenshots or spreadsheets. Plus, you get a real-time view of your compliance status so you’re never caught off guard before an audit. Want to see the automation in action? Request a demo to get 10% off and waived implementation fees. Get a Demo
|
|
|
Business News
-
Tidal Cyber secures $5m seed investment (source)
-
Collaborative defense: Snyk and SentinelOne integrate platforms to bolster cybersecurity (source)
-
Palo Alto Networks snaps up Talon to enhance enterprise browser security (source)
-
Myrror Security seals $6m in seed funding to tackle software supply chain threats (source)
-
Threat-informed defense startup Tidal Cyber raises $5M for platform growth (source)
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌 If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|