<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloud-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/cloud-security/</link><description>Recent content in Cloud-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 22 Aug 2026 11:32:44 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/cloud-security/index.xml" rel="self" type="application/rss+xml"/><item><title>9,300+ Leaked AWS Keys Still Active, Grant Full Account Control</title><link>https://curasec.metacog.co.kr/insights/2026-08-22-hundreds-of-leaked-aws-keys-give-full-control-over-corporate/</link><pubDate>Sat, 22 Aug 2026 11:32:44 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-22-hundreds-of-leaked-aws-keys-give-full-control-over-corporate/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Still-valid exposed AWS keys require no exploitation sophistication — the credential is the exploit. Audit all active IAM access keys in your AWS accounts, cross-reference against the leaked dataset, rotate any keys created or last-used anomalously, and enforce least-privilege policies with automatic key rotation going forward.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active leaked credentials mean unauthorized access may already be occurring. Hunt CloudTrail logs since August 2022 for API calls from unexpected source IPs, new IAM user/role creation, or unusual resource provisioning that could indicate keys were already abused by third parties.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Hundreds of corporate AWS keys with full-account-control scope being publicly available for up to four years is a material risk requiring same-week action — confirm whether your organization&amp;rsquo;s keys appear in the exposed set and direct engineering to complete a credential audit and rotation before end of week.&lt;/li>
&lt;/ul></description></item><item><title>SANS ISC: Observed Scans Targeting Cloud Metadata Service (IMDS)</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-simple-scans-for-cloud-metadata-service-wed-aug-19th/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-simple-scans-for-cloud-metadata-service-wed-aug-19th/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Reinforces the need to enforce IMDSv2 (hop-limit 1, require session tokens) on all EC2/GCP/Azure VMs and audit IAM role assignments to minimize credential scope accessible via the metadata endpoint.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No new IOCs or campaign detail here, but a useful reminder to verify detections exist for unusual internal requests to 169.254.169.254, which can indicate SSRF or compromised workload attempts to harvest credentials.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Snowflake Extortion Actor Pleads Guilty; 165 Orgs, 100M Records Affected</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-canadian-man-pleads-guilty-in-snowflake-extortions/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-canadian-man-pleads-guilty-in-snowflake-extortions/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The 2024 Snowflake credential-stuffing campaign is legally concluded with no new technical disclosures; reinforces that MFA enforcement on cloud data warehouses is non-negotiable, but no immediate action is required if controls were hardened after the original incident.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The guilty plea closes attribution on a major 2024 campaign but surfaces no new IOCs, TTPs, or detection opportunities; useful for building institutional knowledge about the attacker&amp;rsquo;s methods (credential reuse at scale against SaaS platforms).&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A high-profile case closure illustrating the scale of SaaS vendor risk when MFA is absent; valuable reference for board-level narratives on third-party cloud risk and regulatory exposure tied to customer data held by a vendor.&lt;/li>
&lt;/ul></description></item><item><title>UNC6671 Vishing-AiTM Campaign Targets Financial Services, Enterprise Cloud</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-unc6671-rebrands-multi-brand-vishing-extortion-targets-finan/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-unc6671-rebrands-multi-brand-vishing-extortion-targets-finan/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active group uses AiTM to bypass MFA on M365 and Okta; implement phishing-resistant FIDO2/hardware-key MFA and tighten Conditional Access or Okta device-trust policies to invalidate intercepted session tokens.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active campaign with mappable TTPs — hunt for anomalous Okta and M365 session activity (unexpected token origins, bulk SharePoint/OneDrive exfil) since May 2026 and pull the GTIG report for infrastructure IOCs tied to Redact, Pink, Helix, and Falcon brands.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Extortion group is actively hitting financial services, private equity, and professional services — if your org falls in these verticals, brief leadership this week on the campaign and verify that helpdesk impersonation and personal-device contact scenarios are covered in your security awareness program.&lt;/li>
&lt;/ul></description></item><item><title>AWS, Google, and Vercel patch agent flaws that bypass model guardrails</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-aws-google-and-vercel-agent-flaws-let-attackers-trigger-tool/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-aws-google-and-vercel-agent-flaws-let-attackers-trigger-tool/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you operate AI agents on AWS, Google, or Vercel infrastructure, audit your agent configurations and apply vendor patches; the core risk is that tool invocations can be triggered without a model turn, defeating system-prompt and content-filter controls you may rely on for safety.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or active exploitation reported, but this class of agent-layer authorization bypass is worth understanding as AI agent deployments grow — future detections may need to monitor tool-call events that lack a preceding model-turn record.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization uses AI agent frameworks on these three platforms, confirm engineering teams have reviewed and applied patches; this also signals the need for an AI agent security policy that doesn&amp;rsquo;t assume model-layer guardrails are the last line of defense.&lt;/li>
&lt;/ul></description></item><item><title>Canadian pleads guilty to Snowflake data-theft scheme hitting 165 orgs</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The guilty plea closes the legal chapter on a credential-stuffing campaign that bypassed MFA-less Snowflake accounts; no new vulnerability or patch, but reinforces ensuring MFA and session token controls are enforced on all cloud data warehouse accounts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The case confirms 165 organizations were breached through stolen credentials at a single cloud provider, a useful data point for board-level discussions on cloud vendor risk and MFA mandates — no immediate action required given the incident predates this plea.&lt;/li>
&lt;/ul></description></item><item><title>Snowflake Hacker Pleads Guilty; 165 Orgs and 100M Records Exposed</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-snowflake-hacker-pleads-guilty-over-breaches-affecting-at-le/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-snowflake-hacker-pleads-guilty-over-breaches-affecting-at-le/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The guilty plea closes the loop on a major credential-based cloud breach campaign; review whether your org&amp;rsquo;s Snowflake tenant MFA and network policies would have detected or blocked the access patterns used in 2024.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A high-profile conviction in a breach affecting 100M people and 165 orgs is useful context for board discussions on cloud vendor risk and credential-based attack exposure; no immediate action required unless your org was among those affected.&lt;/li>
&lt;/ul></description></item><item><title>FedRAMP 20x Replaces Rev5 With Continuous Evidence Requirements</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-fedramp-rev5-is-ending-what-the-20x-transition-really-requir/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-fedramp-rev5-is-ending-what-the-20x-transition-really-requir/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your team supports a FedRAMP-authorized product, start mapping how you&amp;rsquo;ll generate continuous, machine-readable control evidence — point-in-time assessment artifacts will no longer suffice once the transition deadline arrives.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization holds or pursues FedRAMP authorization, place the Rev5-to-20x transition on the roadmap this quarter: budget for tooling that produces continuous evidence and assess your current ATO timeline against the sunset date. Note this piece appears to be vendor-authored content from Anecdotes, so verify transition specifics against GSA primary sources.&lt;/li>
&lt;/ul></description></item><item><title>Bit2Watt: Cloud GPU Tenants Could Destabilize Data Center Power Grids</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-new-bit2watt-attack-could-let-cloud-tenants-disrupt-power-gr/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-new-bit2watt-attack-could-let-cloud-tenants-disrupt-power-gr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel academic research showing that ordinary tenant GPU workloads can modulate data center power draw enough to stress the upstream grid — no exploit or patch surface exists, but it reshapes how multi-tenant GPU infrastructure risk should be assessed in cloud architecture reviews.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no active exploitation, and no practical detection surface for workload-level power manipulation; file as background awareness on an emerging side-channel class with no near-term hunt or rule-writing opportunity.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Early-stage academic research with no current exploitation; worth tracking as a long-horizon risk narrative around cloud infrastructure resilience and power-grid dependencies, but no board or customer communication is warranted now.&lt;/li>
&lt;/ul></description></item><item><title>Mandiant: Hardening Publicly Exposed Serverless Cloud Functions</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-the-risk-of-exposed-cloud-functions-and-how-to-harden/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-the-risk-of-exposed-cloud-functions-and-how-to-harden/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Mandiant assessments routinely find unauthenticated Cloud Run/Functions exposed to the internet; audit your serverless inventory for missing auth controls and apply the hardening patterns (least-privilege service accounts, input validation, network egress restrictions) this quarter. No active exploitation signals elevate this to Act.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The LFI/RFI and command-injection paths described could inform detection logic for serverless workloads, but there are no IOCs, no named campaign, and no novel TTPs here — no immediate hunt or rule-writing required.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>