Andoni A.'s Avatar

Andoni A.

@andoniaf.unicrons.cloud

Cloud Security Engineer. Writing about cloud security at unicrons.cloud.

30 Followers  |  47 Following  |  29 Posts  |  Joined: 15.10.2023  |  1.8179

Latest posts by andoniaf.unicrons.cloud on Bluesky

Post image

Do you want to build "the perfect pipeline"?

@Paco_S and I will present "Level Up Your CI/CD: Building a secure pipeline with OSS" workshop at @cloudvillage-dc.bsky.social @defcon.bsky.social πŸš€

15.07.2025 11:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

We're at @fwdcloudsec.org and we have stickers. I do not know what else to say so just find us (or the stickers we left around πŸ˜‚)

30.06.2025 21:44 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
FinOps for Engineers: How to create real impact in your organization, Thu, Jun 12, 2025, 6:30 PM | Meetup **Talk: "FinOps for Engineers: How to create real impact in your organization"** Learn about FinOps culture from the engineering point of view and how to create a positive

Is your boss telling you to reduce the bill? Then this meetup is perfect for you!

FinOps for Engineers: How to create real impact in your organization πŸ’Έ
with Ernesto Suarez, CEO at @GlassityStartup

πŸ—“Thu, June 12
⏰⁣18:30h
πŸ“@FlywireEng
office
πŸ“RSVP: www.meetup.com/aws-valencia...

09.06.2025 15:28 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Introducing a New Way to Track AWS Documentation Changes | Miggo Introducing The New Way to Track AWS Documentation Changes

www.miggo.io/resources/in...

17.04.2025 06:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
AWS Security Changes

An AWS Documentation Change Tracker, cool πŸ‘πŸ»

awssecuritychanges.com

17.04.2025 06:31 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Capital One's $200M Cloud Data Breach
YouTube video by Kevin Fang Capital One's $200M Cloud Data Breach

Would you prefer a video? I also have a video. www.youtube.com/watch?v=r7HV...

14.04.2025 16:33 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Steal EC2 Metadata Credentials via SSRF - Hacking The Cloud Old faithful; How to steal IAM Role credentials from the EC2 Metadata service via SSRF.

Never heard about this? No problem.

Take a look to hackingthe.cloud/aws/exploita... to quickly understand how attackers do it.

And this github.com/ramimac/aws-... to understand how common (and old) this kind of attacks are.

14.04.2025 16:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extractΒ EC2 Metadata, which could includeΒ Identity and Access Management (IA...

Friendly reminder: IMDSv2 was released in November 2019.

www.bleepingcomputer.com/news/securit...

14.04.2025 16:09 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
How We Saved $70K/Year with an Open Source Private Cloud CA | Paul Schwarzenberger, Q-Solution
YouTube video by Prowler How We Saved $70K/Year with an Open Source Private Cloud CA | Paul Schwarzenberger, Q-Solution

The talk is already available in YT: www.youtube.com/watch?v=p2Cb...

11.04.2025 13:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Serverless CA on AWS Serverless CA in AWS with FIPS 140-2 level 3 CA key storage and cost typically under $5 per month

"100% serverless Certificate Authority on AWS, only $50/year"

Never thought I would hear all these words togetherπŸ˜…

But it's true, go check this amazing project serverlessca.com by @paulschwarzen

08.04.2025 17:54 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Vaya, parece que @colibid tambiΓ©n retransmite partidos de futbol de forma "ilegal"...

06.04.2025 14:13 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents

"Vibe coders" are in trouble...

www.pillar.security/blog/new-vul...

02.04.2025 07:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub Actions and the Pinning Problem: What 100 Security Projects Reveal Only 7/100 popular security projects pin everything. Here’s what I learned digging into the data.

En casa del herrero, cuchillo de palo. πŸ˜…

medium.com/@adan.alvare...

31.03.2025 06:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Open Cloud Security Conference

Open Cloud Security agenda is out! πŸŽ‰

opencloudsecurity.vfairs.com/en/#agenda

26.03.2025 17:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Research finds 12,000 β€˜Live’ API Keys and Passwords in DeepSeek's Training Data β—† Truffle Security Co. We scanned Common Crawl - a massive dataset used to train LLMs like DeepSeek - and found ~12,000 hardcoded live API keys and passwords. This highlights a growing issue: LLMs trained on insecure code m...

AWS Root Keys in Front-End Code?! Wtf πŸ™ƒ

trufflesecurity.com/blog/researc...

20.03.2025 09:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Cloud vulnerability teardown: what's important and what you can ignore Breaking down the challenges of vulnerabilities in the cloud and how to identify if your team is at risk

groundedcloudsecurity.substack.com/p/vulnerabil...

18.03.2025 09:17 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Psychological safety is NOT about lack of disagreement.

Psychological safety REQUIRES:

* disagreement and debate
* setting standards for behavior and performance, and enforcing them
* telling people things they don't want to hear
* courage, from the bottom up
* humility, from the top down

13.03.2025 23:06 β€” πŸ‘ 267    πŸ” 72    πŸ’¬ 9    πŸ“Œ 6
Post image 10.03.2025 10:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Key takeaways for me:
- "False Positives Rate" as the most important metric for measuring detection eng. success
- "Most detections (42%) were custom-built to fit their organization’s unique envs. Vendor-provided come in second at 37%, but few rely on them exclusively."

10.03.2025 10:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
2025 State of Detection Engineering Report | Anvilogic The 2025 State of Detection Engineering Report reveals key trends & challenges in detection engineeringβ€”from AI adoption to skill gaps and data access.

www.anvilogic.com/report/2025-...

10.03.2025 10:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

I've been accepted as Security AWS Community Builder πŸŽ‰ πŸŽ‰

That means more AWS Cloud Security stuff is coming! πŸ™Œ

#AWSCommunity

05.03.2025 20:35 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I personally hate the term "human error" in this context, but I guess thats's what everyone usually uses.

01.03.2025 11:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Do you agree with this chatGPT definition of "misconfiguration" in a cloud security context?

How would you define it?

01.03.2025 11:02 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

como se entere @sbldevnet.com...

01.03.2025 10:52 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Want to foster a cost-conscious culture in your DevOps team?

We loved this Reddit post (300+ upvotes) about a startup cutting its cloud bill by 40% in weeks by fostering a culture of cost / waste awareness.

24.02.2025 16:30 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
AWS IAM User Enumeration Vulnerabilities: CVE-2025-0693 and Security Implications - SSOJet Two critical username enumeration vulnerabilities were identified in the AWS Web Console, exposing all console-enabled Identity and Access Management (IAM) users to potential risk.

blog.ssojet.com/aws-iam-user...

24.02.2025 16:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Vamos, que mientras sigas cambiando cosas en su sistema nunca serΓ‘ suficiente, pero siempre valdrΓ‘ la pena.

21.01.2025 13:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"If you focus only on the what, it leads inexorably to an ever growing list of out of date dashboards and alerts and runbooks. Adding how or why signals will help you later on with further investigations. It also aids in building up and maintaining intuition about the system..."

21.01.2025 13:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

"every change (not just code!) that affects a system either makes the system more observable, or reduces it's observability. [...] If you aren’t moving forward - working to make the system more observable - you are moving backward - allowing the system to become less observable.

21.01.2025 13:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@andoniaf.unicrons.cloud is following 20 prominent accounts