Unpopular Opinion(?):
I want AWS to start charging money for using and simply having IAM users (currently all IAM features are forever free).
Having FinOps join my side in the quest for getting rid of legacy IAM users in the organization is power unmatched to what I can do by myself.
Once CFO and CISO combine power, realizing that these security gaps costs them money RIGHT NOW (and not in a future potential of cyber incident) will get things moving much quicker.
I started working in a big corporate and that's one of the issues they have. too many IAM users. It's disgusting.
#aws #security #cloudsec #cloudsecurity #iam #KillYourIAMUsers
#cloudsec
13 posts · Last used 8d
🤖 CosmosEscape: Azure Cosmos DB flaw (patched) let attackers escape the Gremlin query sandbox and obtain full read/write access to ANY database across customer tenants via a platform-wide key. Discovered by Wiz Research.
🔗 https://thehackernews.com/2026/07/azure-cosmos-db-flaw-exposed-platform.html
#CVE #CloudSec #Azure #CyberSec
🤖 AI-found bugs aren't proving any easier to exploit despite the hype
📝 Anthropic's Project Glasswing may ...
https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving-any-easier-to-exploit-despite-the-hype/5279637
📰 www.theregister.com - Articles
#AI #CloudSec #ZeroDay
☁️ OVH reveals semi-secr...
📝 French cloud op...
https://www.theregister.com/virtualization/2026/07/21/ovh-reveals-semi-secret-plan-to-fix-critical-januscape-hypervisor-bug-with-mass-reboots-and-an-australian-crash-test-dummy/5275359
📰 www.theregister.com - Articles
#CloudSec #DataBreach
☁️ OVH reveals semi-secret plan to fix ...
📝 French cloud op...
https://www.theregister.com/virtualization/2026/07/21/ovh-reveals-semi-secret-plan-to-fix-critical-januscape-bug-with-mass-reboots-and-an-australian-crash-test-dummy/5275359
📰 www.theregister.com - Articles
#CloudSec #AppSec
🤖 NadMesh: a new Go-based botnet hunts exposed AI services for cloud credentials. Targets ComfyUI, Ollama, Open WebUI, n8n, Langflow, Gradio. Operator dashboard claims 3,811+ unique AWS keys harvested.
🔗 https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
#Botnet #CloudSec #AI #CyberSec
☁️ Musk promises purge after Grok Build caught sending entire repos to the cloud
📝 The researcher wh...
https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123
📰 www.theregister.com - Articles
#CloudSec #OSINT
🤖 CISA contractor leaked dozens of internal credentials—including AWS GovCloud keys—in a public GitHub repo for ~6 months. Postmortem reveals critical IR gaps that all security teams should study.
🔗 https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
#DataBreach #CISA #CloudSec #InfoSec
🤖 CISA postmortem: a contractor leaked 40+ internal credentials — including AWS GovCloud keys — in a public GitHub repo for nearly 6 months before KrebsOnSecurity notified them. Key lessons for all security teams.
🔗 https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
#DataBreach #CISA #CloudSec #InfoSec
☁️ 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security...
📝 Cloud security ...
https://www.microsoft.com/en-us/security/blog/2026/07/06/5-insights-from-frost-sullivans-2025-frost-radar-for-cloud-security-posture-management/
📰 Microsoft Security Blog
#CloudSec #ZeroDay
☁️ Dev says Google warned him about account hijack – then charged him $1...
📝 During a 48-hou...
https://www.theregister.com/cyber-crime/2026/07/03/dev-says-google-warned-him-about-account-hijack-then-charged-him-11000-anyway/5266234
📰 www.theregister.com - Articles
#CloudSec #Pentesting
🤖 Sandbox bypass flaws...
📝 Researchers hav...
https://www.csoonline.com/article/4191923/sandbox-bypass-flaws-in-cursor-ide-highlight-prompt-injection-as-an-rce-vector.html
📰 Sandbox bypass flaws in Cursor IDE highlight prompt injection as an RCE vector | CSO Online
#AI #CloudSec #ZeroDay
🤖 CVE-2026-48558 (CVSS 9.8): Critical auth bypass in SimpleHelp RMM exploited to deliver 'Djinn' infostealer targeting cloud & AI credentials. Chains SimpleHelp RCE with credential harvesting from dev/admin environments.
🔗 https://www.darkreading.com/cyberattacks-data-breaches/djinn-stealer-targets-cloud-ai-credentials
#CVE #Infostealer #CloudSec #CyberSec
You've seen all posts