Scott Piper

Scott Piper

@scottpiper.bsky.social

Cloud security historian. Developed http://flaws.cloud, CloudMapper, and Parliament. Founding team for fwdcloudsec.org Principal Cloud Security Researcher at Wiz.

1,821 Followers 78 Following 198 Posts Joined May 2023
2 weeks ago

Interesting. I didn't know there was one more than region in that partition.

1 0 1 0
3 weeks ago
Preview
CFP | NA 2026 | fwd:cloudsec fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...

Check out the the Call For Papers here: fwdcloudsec.org/conference/n...

2 0 0 0
3 weeks ago

- Practitioners! This is a conference for practitioners. Cross-tenant 0days are fun, but war stories of migrating accounts between Orgs due to M&A, migrating applications from one cloud to another, and other things practitioners do are the meat and potatoes of this conference.

1 0 1 0
3 weeks ago

* How are you securing agents in the cloud?
- Some of you have multiple AWS Organizations. How are you managing an organization of Organizations?

1 0 1 0
3 weeks ago

- AI: Last year we received surprisingly few talks related to AI. 🤯 I know you all are using AI for all sorts of cloud security things. Let's hear about it! Examples:
* How easy was it to migrate CloudFormation to terraform, or to a different cloud, with an LLM to translate?

1 0 1 0
3 weeks ago

- Cloud concepts brought back to datacenters: For years people have turned their old existing datacenters into "clouds", but now you have people who have only ever used the cloud moving to datacenters. What did they bring with them?

1 0 1 0
3 weeks ago

- Neoclouds: CoreWeave, Vercel, and other code execution as-a-service. How are you securing (or abusing) those?
- Multi-partitions: How are you leveraging both AWS standard and European Sovereign Cloud? Any unexpected gotchas in ESC or other partitions?

1 0 2 0
3 weeks ago

It pains me when I hear people say "I thought about submitting a talk to the fwd:cloudsec, but didn't because..." and the reasons are often things I actually want to see presentations on! Some talk ideas I personally want to watch (the other reviewers and I will fight ⚔️):

3 1 1 0
1 month ago
Preview
fwd:cloudsec North America 2026 | fwd:cloudsec fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...

Tickets for fwd:cloudsec North America go on sale today, in about 4 hours, at 10am PST.

fwdcloudsec.org/conference/n...

3 3 0 0
1 month ago
fwd:cloudsec North America 2026 fwd:cloudsec is the industry's leading independent, community-driven cloud security conference. All times listed are in US/Pacific time.

Tickets go on sale next week on Monday, Feb 9, at 10:00 a.m. PST for our North American conference happening near Seattle on June 1 and 2. An additional small batch will go on sale that evening at 11:00 p.m. PST.

Tickets will be available for purchase here: www.eventbrite.com/e/fwdcloudse...

1 1 1 0
1 month ago

@fwdcloudsec.org is an awesome conference. Looking forward to seeing lots of cool submissions into the CFP!

1 1 0 0
1 month ago
Preview
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.

Did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset.

It's the EICAR test string of the AI age. Details:

hackingthe.cloud/ai-llm/explo...

10 1 0 0
1 month ago

We've locked in dates and venues for the North American (NA) and European (EU) fwd:cloudsec conferences this year!

fwd:cloudsec NA will be in the Seattle, Washington area at the Meydenbauer Center in Bellevue on June 1 and 2. 🧵

14 7 1 1
1 month ago

What are we calling normal AWS now? Normal, standard, classic, commercial, global, american?

How do you say out loud the acronym for AWS European Sovereign Cloud? I'm calling it "oosk", because the region is eusc-de-east-1, which sounds like a riff on the techno onomatopoeia "boots and cats".

3 0 1 0
1 month ago

The most surprising thing about AWS ESC is there aren't any cookie acceptance popup windows in the console. Is this really European?

3 0 1 0
1 month ago
Preview
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.

Very cool research on a CodeBuild misconfiguration which could have had significant consequences. I’m a bit disappointed that there wasn’t more done to secure the supply chain after the Q Developer incident.
www.wiz.io/blog/wiz-res...

3 2 0 0
1 month ago
Preview
Opening the AWS European Sovereign Cloud AWS European Sovereign Cloud is now generally available, offering EU-based organizations independent cloud infrastructure with enhanced sovereignty controls, E...

The AWS European Sovereign Cloud (ESC) has launched!

aws-news.com/article/2026...

4 1 1 0
1 month ago
Preview
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.

This seems bad.

www.wiz.io/blog/wiz-res...

20 6 0 1
2 months ago

December is generally a good time for gifts, and I have a special one for you.

We are glad to announce fwd:cloudsec Europe 2026: September 7th and 8th - London, UK 🇬🇧

More info to come early 2026. Stay tuned, folks.

6 1 0 0
2 months ago
Preview
Cryptomining campaign targeting Amazon EC2 and Amazon ECS | Amazon Web Services Amazon GuardDuty and our automated security monitoring systems identified an ongoing cryptocurrency (crypto) mining campaign beginning on November 2, 2025. The operation uses compromised AWS Identity ...

This is the best write-up on threat actor tradecraft I've seen from AWS. aws.amazon.com/blogs/securi...

2 1 0 0
3 months ago
Preview
Top AWS re:Invent Announcements for Security Teams in 2025 | Wiz Blog The re:Invent announcements that are most impactful to security teams.

My top picks from re:Invent security announcements: www.wiz.io/blog/top-aws...

6 1 0 2
3 months ago
Keeping Secrets Out of Logs There's no silver bullet, but if we put some "lead" bullets in the right places, we have a good shot at keeping sensitive data out of logs.

This is excellent. Also available in video.
allan.reyes.sh/posts/keepin...

h/t tldrsec

5 0 0 0
3 months ago
Preview
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.

It’s time to bust some malware! 🦠

Challenge #6 “Malware Busters” is LIVE.
Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside.
Think you can crack it?

cloudsecuritychampionship.com/challenge/6

2 1 0 0
3 months ago
Preview
Shai-Hulud 2.0: Ongoing Supply Chain Attack | Wiz Blog Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users.

🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast.
Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation.
Details: www.wiz.io/blog/shai-hu...

5 3 0 1
3 months ago
Preview
Skyway: Cloud cost management for the 9-figure club Introducing Skyway: contract management for enterprise cloud spend. Built by the team overseeing tens-of-billions in enterprise cloud spend.

The day has come where we get to announce what we've been working on for the past year 😍

www.duckbillhq.com/blog/skyway-...

16 3 4 1
4 months ago
Backyard APT: A Raccoon Story Raccoons are both advanced and persistent threats. After one attacked my chihuahua Jolene, I declared war on my backyard invaders. Through ultrasonic deterrents, motion-activated sprinklers, and wacky...

My favorite security story I've read this year 😂, a story of surprising turns by Alex Smolen: engseclabs.com/blog/raccoon...

1 1 0 0
4 months ago
Post image

Yuval Avrahami was ranked as the top Azure researcher by Microsoft this quarter! He has made a Kubernetes focused CTF for the Wiz Cloud Security Championship, check it out! cloudsecuritychampionship.com
Also if you can find cloud zero days, check out www.zeroday.cloud with a $4.5M prize pool!

3 0 0 0
4 months ago

I feel like the biggest takeaway from the latest AWS outage is that there’s simply no architecting around them at this point. Even if you are 100% redundant/multi-whatever, your vendors and customers are certainly not. Order volume is dropping no matter what you do. We’re all in this together.

28 2 4 1
4 months ago

I used to drink a gallon of milk a day, so this is just being more efficient.

0 0 0 0
4 months ago
Preview
Stephen Gutowski on X: "Jeep just pushed a software update that bricked all the 2024 Wrangler 4xe models, including my Willys. The future is going great." / X Jeep just pushed a software update that bricked all the 2024 Wrangler 4xe models, including my Willys. The future is going great.

Jeep pushed a bad update on Friday that has been bricking 2024 Wrangle 4xe's. x.com/StephenGutow...

0 0 0 0