⤷ Title: IAM Fundamentals: Users, Groups, Roles & Policies
════════════════════════
𐀪 Author: Paraskhorwal
════════════════════════
ⴵ Time: Sun, 27 Sep 2026 10:30:48 GMT
════════════════════════
⌗ Tags: #information_security #aws #cloud_computing #bugbounty_writeup #cybersecurity
════════════════════════
𐀪 Author: Paraskhorwal
════════════════════════
ⴵ Time: Sun, 27 Sep 2026 10:30:48 GMT
════════════════════════
⌗ Tags: #information_security #aws #cloud_computing #bugbounty_writeup #cybersecurity
Medium
IAM Fundamentals: Users, Groups, Roles & Policies
Before you can understand AWS privilege escalation, you need to understand the identities that receive permissions and the policies that…
⤷ Title: An API Key and an OAuth Token Differ by One Field, and That Field Decides Who Kills the Credential
════════════════════════
𐀪 Author: Ghost Accounts
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 02:55:44 GMT
════════════════════════
⌗ Tags: #oauth #cloud_security #identity_management #devsecops #api_security
════════════════════════
𐀪 Author: Ghost Accounts
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 02:55:44 GMT
════════════════════════
⌗ Tags: #oauth #cloud_security #identity_management #devsecops #api_security
Medium
An API Key and an OAuth Token Differ by One Field, and That Field Decides Who Kills the Credential
An API key identifies the project or application behind a request. An OAuth access token identifies a principal and carries a scope and an…
⤷ Title: [pwnedlabs AWS] Access Secrets with S3 Bucket Versioning
════════════════════════
𐀪 Author: Ayush
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 17:07:19 GMT
════════════════════════
⌗ Tags: #ctf_writeup #penetration_testing #aws_security #cloud_security #cybersecurity
════════════════════════
𐀪 Author: Ayush
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 17:07:19 GMT
════════════════════════
⌗ Tags: #ctf_writeup #penetration_testing #aws_security #cloud_security #cybersecurity
Medium
[pwnedlabs AWS] Access Secrets with S3 Bucket Versioning
Lab link
⤷ Title: Microsoft Links JADEPUFFER Azure Attack to Agentic Ransomware Actor Storm-3168
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 06:11:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #agentic ransomware #Azure #Cloud Security #JADEPUFFER #Microsoft #ransomware #service principals #Storm_3168 #Sysdig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 06:11:37 +0000
════════════════════════
⌗ Tags: #Cybercriminals #agentic ransomware #Azure #Cloud Security #JADEPUFFER #Microsoft #ransomware #service principals #Storm_3168 #Sysdig
Daily CyberSecurity
Microsoft Links JADEPUFFER Azure Attack to Agentic Ransomware Actor Storm-3168
Two stolen Azure identities gave one attacker control over an entire cloud tenant in June 2026. According to new research from Microsoft Security, the JADEPUFFER Azure attack wiped most of the sto…
⤷ Title: OpenAI Dots AI Assistant Gets Its Own Cloud Computer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:24:54 +0000
════════════════════════
⌗ Tags: #Technology #Agent Security #AI Agents #AI Assistant #Cloud Computer #Dots #Microsoft Teams #OpenAI #Slack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 08:24:54 +0000
════════════════════════
⌗ Tags: #Technology #Agent Security #AI Agents #AI Assistant #Cloud Computer #Dots #Microsoft Teams #OpenAI #Slack
Daily CyberSecurity
OpenAI Dots AI Assistant Gets Its Own Cloud Computer
OpenAI Unveils Dots, the Always-On Assistant OpenAI has formally revealed the persistent AI assistant that was once rumored under the codename “O.” Its name is Dots. OpenAI positions t…
⤷ Title: CISA Warns of Unpatched CVSS 10 Flaw in Viidure Dashcam App Exposing Footage and Firmware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 01:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #cloud storage #CVE_2026_94204 #CVE_2026_96587 #dashcam security #hardcoded credentials #Viidure #Viidure dashcam app
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 01:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #cloud storage #CVE_2026_94204 #CVE_2026_96587 #dashcam security #hardcoded credentials #Viidure #Viidure dashcam app
Daily CyberSecurity
CISA Warns of Unpatched CVSS 10 Flaw in Viidure Dashcam App Exposing Footage and Firmware
TL;DR CISA published advisory ICSA-26-272-07 on September 29, 2026, covering two flaws in the Viidure dashcam app for Android. The worst, CVE-2026-96587, scores a maximum CVSS 10.0 for hardcoded c…
⤷ Title: Part 1: How I Started Building a Cybersecurity Policy for ISO 27017 at a Local Cloud Provider
════════════════════════
𐀪 Author: Vadym
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 08:50:18 GMT
════════════════════════
⌗ Tags: #infosec #information_security #cybersecurity #iso_27001 #cloud_security
════════════════════════
𐀪 Author: Vadym
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 08:50:18 GMT
════════════════════════
⌗ Tags: #infosec #information_security #cybersecurity #iso_27001 #cloud_security
Medium
Part 1: How I Started Building a Cybersecurity Policy for ISO 27017 at a Local Cloud Provider
What I’ve learned so far, and what other cloud providers should know before they start
⤷ Title: My First AWS IAM Enumeration Lab with CloudGoat
════════════════════════
𐀪 Author: Umang Mishra
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 07:38:05 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #penetration_testing #cloud_security #aws
════════════════════════
𐀪 Author: Umang Mishra
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 07:38:05 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #penetration_testing #cloud_security #aws
Medium
My First AWS IAM Enumeration Lab with CloudGoat
I recently started learning more about AWS Cloud Security as part of my CPENT preparation.
⤷ Title: AWS IAM Policy Evaluation Logic: How AWS Decides Whether a Request Is Allowed
════════════════════════
𐀪 Author: Paraskhorwal
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 17:17:29 GMT
════════════════════════
⌗ Tags: #aws #information_security #cloud_computing #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Paraskhorwal
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 17:17:29 GMT
════════════════════════
⌗ Tags: #aws #information_security #cloud_computing #bug_bounty #cybersecurity
Medium
AWS IAM Policy Evaluation Logic: How AWS Decides Whether a Request Is Allowed
An IAM policy that contains Allow is only one part of the authorization decision. To understand AWS access, you need to understand implicit…
⤷ Title: AWS Fixes Loom for AWS Admin Takeover and SageMaker Unified Studio Code Execution Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 22:09:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agent Security #AWS #Cloud Security #CVE_2026_103956 #CVE_2026_103957 #CVE_2026_104019 #Loom for AWS #SageMaker Unified Studio
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 22:09:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Agent Security #AWS #Cloud Security #CVE_2026_103956 #CVE_2026_103957 #CVE_2026_104019 #Loom for AWS #SageMaker Unified Studio
Daily CyberSecurity
AWS Fixes Loom for AWS Admin Takeover and SageMaker Unified Studio Code Execution Flaws
TL;DR AWS published two security bulletins on October 2, 2026, covering four CVEs. Three hit Loom for AWS, an open-source AI agent platform, including an admin takeover bug. The fourth lets a Sage…