DEV Community

#cloudsecurity

Securing cloud environments like AWS, Azure, and GCP, including configurations and services.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I Attacked My Own AWS API Four Times, Then Fixed It, and Wrote Down Everything

I Attacked My Own AWS API Four Times, Then Fixed It, and Wrote Down Everything

Comments 3
12 min read
How Attackers Abuse Firebase Misconfigurations in Production Apps

How Attackers Abuse Firebase Misconfigurations in Production Apps

Comments
2 min read
I Deleted Production at 6 PM on a Friday. Here's Why It Was Fine.

I Deleted Production at 6 PM on a Friday. Here's Why It Was Fine.

4
Comments
3 min read
The Finding That Hasn't Fired Yet

The Finding That Hasn't Fired Yet

1
Comments
8 min read
I Audited Our AI Platform and Found Critical Security Gaps

I Audited Our AI Platform and Found Critical Security Gaps

Comments
3 min read
Your Detection Rules Have Ten Years of Windows Logic and Zero Lines for a Stolen IAM Key

Your Detection Rules Have Ten Years of Windows Logic and Zero Lines for a Stolen IAM Key

Comments
3 min read
The Sandbox Had One Allowed Egress Path. The Model Used it to Escape.

The Sandbox Had One Allowed Egress Path. The Model Used it to Escape.

2
Comments
7 min read
Cloud Security Misconfigurations: Common Problems and How to Prevent Them

Cloud Security Misconfigurations: Common Problems and How to Prevent Them

Comments
6 min read
I Gave My AI Assistant the Keys to My Cloud. Here's Why I'm Not Worried.

I Gave My AI Assistant the Keys to My Cloud. Here's Why I'm Not Worried.

6
Comments 6
3 min read
Try GreenOps Scan Safely: Create a Read-Only AWS Profile First

Try GreenOps Scan Safely: Create a Read-Only AWS Profile First

Comments
4 min read
Writing an IAM Policy That's Actually Least Privilege

Writing an IAM Policy That's Actually Least Privilege

Comments
8 min read
Kubernetes Pod Security Standards (PSS) & Native Admission Control

Kubernetes Pod Security Standards (PSS) & Native Admission Control

Comments
4 min read
Cilium eBPF & Tetragon: Cloud-Native Runtime Security & Network Enforcement

Cilium eBPF & Tetragon: Cloud-Native Runtime Security & Network Enforcement

Comments
5 min read
IAM Roles Anywhere: AWS Access With Zero Static Keys

IAM Roles Anywhere: AWS Access With Zero Static Keys

Comments 1
6 min read
51 Findings in SadCloud: What a Verifier Sees That Scanners Frame Differently

51 Findings in SadCloud: What a Verifier Sees That Scanners Frame Differently

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.