Release Date: 03/03/2024 | Issue: 227
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with the cloud security industry. Hand-curated by Marco Lancini.
Sponsor

How did a top tier global financial services institution solve their Kubernetes authentication, RBAC, and multi-tenancy challenges?
  • Satisfied security and compliance requirements
  • Provide a great experience for developers
  • Secure support for dashboards and UIs
  • Decrease load on cluster support staff
  • 100% Open Source
Find out how in our case study (no registration required)

This week's articles


Navigating the Cloud: Exploring Lateral Movement Techniques
Some lateral movement techniques observed in the wild within cloud environments.   #attack   #aws   #azure   #gcp


Hacking Terraform State for Privilege Escalation
What can an attacker do if they can edit Terraform state? The answer should be 'nothing' but is actually 'take over your CI/CD pipeline'.   #attack   #ci/cd   #terraform


Passkeys - Threat modeling and implementation considerations
Post reviewing the current state of the technology from a security standpoint and discussing some critical aspects of passkey implementation.   #explain


Security Centralization for AWS Multi-account using Native Services
Post going through native tools that we can utilize to centralize compliance, logging, monitoring, and user & access management through multi-accounts in an organization.   #aws   #defend


The state of ABAC on AWS (in 2024)
Scott Piper checked in on "The state of ABAC on AWS" back in 2020. Things are only a little better.   #aws   #explain   #iam


Extracting Sensitive Information from the Azure Batch Service
Attackers with Reader access to Batch can: read sensitive data from job outputs and gain access to SAS tokens for Storage Account files attached to the jobs.   #attack   #azure


The Most Dangerous Entra Role You've (Probably) Never Heard Of
Entra ID has a built-in role called "Partner Tier2 Support" that enables escalation to Global Admin, but this role is hidden from view in the Azure portal GUI.   #attack   #azure

Sponsor

Compete in a CTF Cloud Security Challenge
Join Lacework for a virtual Cloud Security Capture the Flag Challenge on March 19. Youโ€™ll have one hour to complete as many challenges as possible. Plus, the top 3 scorers will win a Valve Steam Deck. Attendance is limited, so register now to secure your spot.
Sign up now for your chance to win

Tools


pingora
A library for building fast, reliable and evolvable network services. You can also refer to the companion blog post.


pql
Pipelined Query Language. You can also refer to the companion blog post.


PyRIT
The Python Risk Identification Tool for generative AI (PyRIT) is an open access automation framework to empower security professionals and machine learning engineers to proactively find risks in their generative AI systems. You can also refer to the companion blog post.


lotp
Living Off The Pipeline tools.


public-file-browser-for-amazon-s3
Sample code to deploy a website and a "public files" S3 bucket which can be loaded with any files an administrator wishes to publish publicly online.


gitlab-secrets
This tool analyzes a given GitLab repository and searches for dangling or force-pushed commits containing potential secret or interesting information.

From the cloud providers


#AWS   Enhance container software supply chain visibility through SBOM export with Amazon Inspector and QuickSight
How to can export software bills of materials (SBOMs) for your containers by using an AWS native service, Amazon Inspector, and visualize the SBOMs through Amazon QuickSight.


#AWS   How to develop an Amazon Security Lake POC
How to plan and implement a proof of concept for Security Lake to help you determine the functionality and value of Security Lake in your environment.


#AWS   AWS Incident Detection and Response now offers five minute response time for critical incidents
With this release, AWS IMEs engage you within five minutes of an alarm trigger or in response to a critical support case you raise to AWS Incident Detection and Response.


#AWS   How to use Regional AWS STS endpoints
This blog post provides recommendations that you can use to help improve resiliency in the unlikely event of disrupted availability of the global (now legacy) AWS Security Token Service (AWS STS) endpoint.


#GCP   How to prevent lateral movement techniques on Google Cloud
Post explaining the misconfigurations that could potentially allow a malicious actor to move laterally, and recommending protection methods that can help secure your Google Cloud environment.


#GCP   Want your cloud to be more secure? Stop using service account keys
There are no simple solutions to securing cloud credentials, but one way to get started is to stop using service account keys. Here's how.


#GCP   Design your Landing Zone - Design Considerations Part 1
The article discusses key considerations for designing a Google Cloud Landing Zone as part of cloud adoption, focusing on scalability, security, and governance to ensure a structured and efficient cloud environment.


#AZURE   Get the most out of Microsoft Copilot for Security with good prompt engineering
Effective prompts give Copilot for Security adequate and useful parameters to generate valuable responses.

Thanks for reading!

If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! ๐Ÿ‘Œ

If you have questions, comments, or feedback, let me know on Twitter (@lancinimarco / @CloudSecList), or at feedback.cloudseclist.com!

Thanks,
Marco
Forward Forward
Twitter Tweet
Share Share

How did you like this issue of CloudSecList?

1       2       3       4       5

Archives View in browser Sponsorship
ยฉ 2019-present CloudSecList ยท Marco Lancini