nrw.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Wir sind eine freundliche Mastodon Instanz aus Nordrhein-Westfalen. Ob NRW'ler oder NRW-Sympathifanten, jeder ist hier willkommen.

Serverstatistik:

2,8 Tsd.
aktive Profile

#GCP

14 Beiträge8 Beteiligte3 Beiträge heute

Whoa, things are really heating up again in the cloud world... GCP, Azure, AWS – seems like there's trouble brewing everywhere! 🤯

Seriously, these privilege escalation bugs that keep popping up, like the recent "ConfusedComposer," are a *major* headache.

Look, we all know the cloud offers amazing capabilities, right? But we absolutely *cannot* let security take a backseat. That brings us straight to IAM: it's all about permissions, permissions, permissions! You really can't hammer that home enough.

And hey, don't just rely on your automated tools. They're definitely helpful, no doubt, but they simply won't catch *everything*. Remember to factor in manual pentests too, folks. They're crucial.

So, spill the beans: how are *you* keeping your cloud infrastructure locked down tight these days? Got any insider tips or tricks you're willing to share? 🤔

#CloudSec#Pentest#AWS

Another 250,000 requests to the LVFS at 4AM this morning, ~27 parallel "security scans" from the same IP with routes containing phpMyAdmin, servicedesk, tomcat, wp-content, cgi-bin etc.

I've reported it to #GCP, and if I again get no response from them I'll just block the entire AS396982 range which is hilariously 21M domains and 14M IPv4 addresses.