Cloud Security Wire
AWS Azure GCP RSS
Featured
AWS Misconfiguration critical

AWS IAM Privilege Escalation: PassRole and CreatePolicyVersion Attack Paths

A deep-dive into two of the most dangerous AWS IAM misconfigurations -- iam:PassRole abuse and iam:CreatePolicyVersion -- with exploitation chains, detection opportunities, and remediation guidance.

By Cloud Security Wire · Read analysis →
Coverage
AWS 28
Azure 23
GCP 17
Total 66

Latest Analysis

View all →
AWS Misconfiguration high

AWS Route 53 Resolver: DNS Attack Paths and Hardening Guide

AWS Route 53 Resolver is often misconfigured to allow unrestricted inbound and outbound query forwarding across VPCs and accounts. This creates attack paths for DNS-based data exfiltration, C2 tunnelling, and cross-account reconnaissance that bypass security group controls. Covers misconfiguration patterns, attack chains, CLI detection, and hardening.

Cloud Security Wire ·
Read →
GCP Misconfiguration high

GCP Cloud Functions Security: Unauthenticated HTTP Triggers and Service Account Privilege Escalation

Google Cloud Functions is one of the most common sources of cloud security misconfigurations: HTTP trigger functions deployed without authentication, overprivileged service accounts attached at the project level, and secrets exposed in environment variables. This guide covers each risk with gcloud CLI detection and remediation.

Cloud Security Wire ·
Read →
GCP Hardening Guide high

GCP Cloud Build Security: Secrets, Artifact Poisoning, and CI/CD Hardening

Google Cloud Build pipelines routinely leak secrets, run with overprivileged service accounts, and produce unsigned artifacts. This guide covers the five most common Cloud Build security failures — plaintext secrets, over-scoped service accounts, build log exfiltration, unsigned artifacts, and missing audit configuration — with gcloud remediation for each.

Cloud Security Wire ·
Read →
Topics
#Route 53#DNS#Route 53 Resolver#DNS tunnelling#data exfiltration#multi-account#VPC#C2#AWS#hardening#2026#azure#azure-openai#ai-studio#ai-foundry#ai-search
Stay informed

Cloud security analysis to your RSS reader.

Subscribe via RSS