#cloudsecurity

40 posts · Last used 8d

Unpopular Opinion(?): I want AWS to start charging money for using and simply having IAM users (currently all IAM features are forever free). Having FinOps join my side in the quest for getting rid of legacy IAM users in the organization is power unmatched to what I can do by myself. Once CFO and CISO combine power, realizing that these security gaps costs them money RIGHT NOW (and not in a future potential of cyber incident) will get things moving much quicker. I started working in a big corporate and that's one of the issues they have. too many IAM users. It's disgusting. #aws #security #cloudsec #cloudsecurity #iam #KillYourIAMUsers
0
0
0
0
#GetFediHired #FediHire : I'm looking for a job (EU-remote, preferably part-time). I have 12+ years of experience in security, from PhD to security engineer and security architect. I know my way around #ThreatModelling, #appsec , Hashicorp #Vault, #devsecops , #Kubernetes security, #Gatekeeper, infrastructure/#cloudsecurity, IAM/RBAC, #Keycloak and many other things. Also I'm able to pick up new things fairly quickly. I'm generally quite thorough, and good at paying attention to details (which I think is essential in security). If you need some experienced security engineer or architect, or know someone who does, let's talk!
0
1
4
0
Zapscape (CVE-2026-64561) is another reminder that the hypervisor boundary is only as strong as the code implementing it. The vulnerability is a guest-to-host escape in Linux KVM's x86 Shadow MMU. The root cause is a stale-root validation ordering bug that allows the page fault handler to continue using an invalidated shadow MMU root after quota reclaim, ultimately leading to a use-after-free primitive. Public research demonstrates a complete guest-to-host escape chain, although exploitation requires privileged code execution inside an L1 guest and nested virtualization exposure. I put together a deep technical analysis covering the Shadow MMU internals, nested virtualization, exploitation stages, cross-cache reallocation, KASLR bypass, AMD vs. Intel trigger conditions, the upstream fix, and why simply moving a stale-root check eliminates the entire exploitation chain. Interested to hear how others assess the practical risk for multi-tenant KVM deployments where nested virtualization is enabled. https://thecybersecguru.com/news/zapscape-cve-2026-64561-kvm-guest-host-escape/ #Linux #KVM #Virtualization #KernelSecurity #CloudSecurity #CVE202664561
1
0
0
0
Replying to
Microsoft has patched this. Researcher Shay Shavit will be demonstrating the full horror at Black Hat USA. Review your Azure Automation account identity exposure and apply Microsoft's security updates immediately. Reward: You've received the Binding Arbitration Bracer — it does nothing, but you clicked Accept, so here we are. #AzureSecurity #CloudSecurity #CyberSecurity #IdentityTheft #Microsoft #AchievementUnlocked (3/3)
0
0
0
0