#cloudsec

Offensive Sequenceoffseq@infosec.exchange
2025-12-19

🚨 CRITICAL: CVE-2025-65037 in Azure Container Apps enables unauthenticated remote code injection (CVSS 10). No patch yet — restrict access, monitor for attacks, update IR plans. Full advisory: radar.offseq.com/threat/cve-20 #OffSeq #Azure #CloudSec #Vulnerability

Critical threat: CVE-2025-65037: CWE-94: Improper Control of Generation of Code ('Code Injection') in Microsoft Azure
Offensive Sequenceoffseq@infosec.exchange
2025-10-26

🚩 CoPhish phishing campaign (HIGH severity) targets Copilot Studio agents to steal OAuth tokens — enabling session hijack & cloud access. No CVE. User training, OAuth app reviews, and token monitoring are key. Details: radar.offseq.com/threat/new-co #OffSeq #OAuth #Phishing #CloudSec

High threat: New CoPhish attack steals OAuth tokens via Copilot Studio agents
Offensive Sequenceoffseq@infosec.exchange
2025-10-23

⚠️ HIGH-severity operational risk: the remediation gap in multi-tool cloud environments delays fixing critical vulnerabilities. Solutions like Pentera Resolve automate and unify workflows, reducing exposure and ensuring compliance. More info: radar.offseq.com/threat/bridgi #OffSeq #VulnMgmt #CloudSec

Critical threat: Bridging the Remediation Gap: Introducing Pentera Resolve
2025-09-13

Dear fantastic BSides community.

So here it is, the #BSidesLuxembourg2026 date announcement!!

We’re expanding into a 3-day event! It will be very exciting, we hope you all agree !?

May 6th will be exclusively for workshops.
May 7-8th will be for various talk tracks, tracks to be determined at a later stage but might include:

1 #Offsec
2. #CloudSec
3. #SOC
4. Etc

Do you have a track idea? Shoot it at us!

#bsides
Feel free to boost, fam.

Claus Cramon Houmannclaushoumann
2025-08-18

Tickets booked for - hope to meet some new and old faces there!

Tanya Janca | SheHacksPurple :verified: :verified:SheHacksPurple@infosec.exchange
2025-08-13

🎥 Missed one of my past conference talks? Let’s fix that.

I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

“Cloud Native Security; Explained”
📽️ twp.ai/4ipSVP

#CyberSecurity #SecurityAwareness #cloudsec #cloud #cloudnative

Tanya Janca | SheHacksPurple :verified: :verified:SheHacksPurple@infosec.exchange
2025-07-18

🎥 Missed one of my past conference talks? Let’s fix that.

I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

“Cloud Native Security; Explained”
📽️ twp.ai/4iosID

#CyberSecurity #SecurityAwareness #cloudsec #cloud #cloudnative

Offensive Sequenceoffseq@infosec.exchange
2025-07-16

🚨 CRITICAL vuln (CVE-2025-49831) in CyberArk Conjur OSS <1.22.1 & Secrets Manager, Self-Hosted (<13.5.1, 13.6): Improper auth enables rerouting of AWS creds via misconfigured networks. Upgrade immediately! radar.offseq.com/threat/cve-20 #OffSeq #CyberArk #Vuln #CloudSec

Critical threat: CVE-2025-49831: CWE-287: Improper Authentication in cyberark conjur
Tanya Janca | SheHacksPurple :verified: :verified:SheHacksPurple@infosec.exchange
2025-06-24

🎥 Missed one of my past conference talks? Let’s fix that.

I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.

“Cloud Native Security; Explained”
📽️ twp.ai/4in9re

#CyberSecurity #SecurityAwareness #cloudsec #cloud #cloudnative

2025-04-23

@fwdcloudsec Europe is offering need-based scholarships for students in the infosec field or those looking to transition. The scholarship covers a complimentary ticket and a stipend for travel costs.

🗓️ Apply by 13th July 2025 at 23:59 CET (UTC+1).

Priority is given to those living within a 4-hour flight to Berlin.

For more info, visit: fwdcloudsec.org/conference/eur

#CloudSec #Infosec #Scholarship #CyberSecurity #Berlin #TechConference #StudentOpportunities #europe #cybersecurity

2025-04-21

🔐 Gamma AI is now being used to craft pixel-perfect phishing pages.
These attacks mimic cloud login portals, flip JavaScript behavior, and bypass email filters.

📉 We break it all down in our latest article:
— Real misuse cases
— MITRE TTP matrix
— Python detection script
— Visual trust infographic

📖 Read it here: open.substack.com/pub/teamivit

#CyberSecurity #GammaAI #LLMSecurity #CloudSec #Phishing #Infosec

Lord Kusuriya ​:tower:​kusuriya@hackers.town
2025-03-28

Hot take, If you develop for cloud environments you need to get used to a default deny on egress and only allow dependencies to be pulled during the build phase. You should know exactly what is talking to where and why. allow all on egress is the equivalent to I chmod 777'd it and it works so whatever...

#cloudsecurity #CloudSec #HotTake #Infosec

2025-03-24

Neida, bloggen var ikke død! Vi har skrevet en rapport om bruk av skyen for kritisk OT - se sammendrag her: infosec.sintef.no/informasjons (og link til hele rapporten) #cloudsec #cybersec #OT

Claus Cramon Houmannclaushoumann
2025-03-20

In the Cloud, is

Fight me.

Valdemarheyvaldemar
2025-03-14

🚀 Container Security in 2025: 7 Must-Know Best Practices!

🐳 As a Captain, I break down supply chain attacks, misconfigurations & more—with live demos of Docker Scout & Snyk!

youtu.be/EoeoCTZAGuU?si=TUalNc

Bruber CloudSecOps :donor:bp4151@infosec.exchange
2025-01-25

It's been a minute since I've posted anything relevant.

Back in August, we made a recommendation to our leadership to realign our teams so we could better support our internal customers. As a result, on Jan 1st I picked up two more engineers on my team and took over our Cloud Security operations. We're still doing a lot of traditional AppSec work from an advisory and/or training perspective, but now we get to play in the Cloud space.

Its been a wild ride, gutting and building out a whole new program. Hopefully by end of the fiscal year, we'll have a solid new program built to scale with all processes at least partially automated.

#appsec #cloudsec

Gonçalo ValÊriodethos@s.ovalerio.net
2024-11-09

"An open-source collection of cloud infrastructure best practices, for bootstrapping your own cloud platform."

cloudguardrails.com/

#security #cybersecurity #cloud #cloudsec

Gonçalo ValÊriodethos@s.ovalerio.net
2024-08-10

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst