Release Date: 17/03/2024 | Issue: 229
Know someone who'd find this useful? Forward this email
CloudSecList is a newsletter for busy professionals who want to keep up to date with cloud security and its intersection with AI. Hand-curated by Marco Lancini since 2019.
Sponsor
How did a top tier global financial services institution solve their Kubernetes authentication, RBAC, and multi-tenancy challenges?
CISA and the National Security Agency (NSA) released five joint Cybersecurity Information Sheets (CSIs) to provide organizations with recommended best practices and/or mitigations to improve the security of their cloud environments.
#defend #strategy
The NSA is releasing "Top Ten Cloud Security Mitigation Strategies" to inform cloud customers about important security practices as they shift their data to cloud.
#defend #strategy
A CTF designed to challenge your Kubernetes hacking skills through a series of critical network vulnerabilities and misconfigurations.
#attack #kubernetes
NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters. You can also refer to the companion blog post.
CloudGrappler is a purpose-built tool designed for effortless querying of high-fidelity and single-event detections related to well-known threat actors in popular cloud environments such as AWS and Azure. You can also refer to the companion blog post.
Now you can use Microsoft Entra ID authentication on Azure Cosmos DB for PostgreSQL clusters in addition or instead of the native Postgres authentication.