从AWS泄露密钥到数据窃取仅需60秒:我们准备好了吗?
注:本文翻译自 Adan Álvarez[1] 的文章《From Leaked AWS Key to Data Exfiltration in 60 Seconds: Are We Ready?》[
阅读全文注:本文翻译自 Adan Álvarez[1] 的文章《From Leaked AWS Key to Data Exfiltration in 60 Seconds: Are We Ready?》[
阅读全文注:本文翻译自 Cloudflare 的文章《How Cloudflare responded to the “Copy Fail” Linux vulnerability》[1],可点击文末“阅读
阅读全文注:本文翻译自 Juliet 的文章《Dirty Frag in Kubernetes: EKS and GKE Exposed With Unset Seccomp》[1],可点击文末“阅读原文”
阅读全文注:本文翻译自 Doyensec 的文章《The Danger of Multi-SSO AWS Cognito User Pools》[1],可点击文末“阅读原文”按钮查看英文原文。全文如下:背景
阅读全文注:本文翻译自 Juliet 的文章《Argo CD CVE-2026-43824: Read-Only App Access and Secret Exposure》[1],可点击文末“阅读原文”
阅读全文注:本文翻译自 Juliet 的文章《Copy Fail in Kubernetes: RuntimeDefault Did Not Block AF_ALG》[1],可点击文末“阅读原文”按钮查看
阅读全文注:本文翻译自 Elastic Security Lab 的文章《CI/CD pipeline abuse: the problem no one is watching》[1],可点击文末“阅读原
阅读全文注:本文翻译自 Sonrai Security 的文章《Global S3: Another C2 Channel for AgentCore Code Interpreters》[1],可点击文末
阅读全文注:本文翻译自Alexis Obeng[1]的文章《Automating Kubernetes Security Labs with Ludus》[2],可点击文末“阅读原文”按钮查看英文原文。全文
阅读全文注:本文翻译自 Unit42 的文章《Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Mul
阅读全文注:本文翻译自 Reversec 的文章《It's Just a Matter of Time: Backdooring Conditional Access Policies》[1],可点击文末“
阅读全文注:本文翻译自 ORCA Security 的文章《Kyverno SSRF: Breaking Kubernetes Namespace Isolation (CVE-2026-4789)》[1]
阅读全文注:本文翻译自 Cyera 的文章《One Megabyte to Root: How a Size Check Broke Docker’s Last Line of Defense》[1],可点
阅读全文注:本文翻译自 r0keb[1] 的文章《VMware Guest To Host》[2],可点击文末“阅读原文”按钮查看英文原文。全文如下:一、引言早上好!今天我们将完整演示如何在 VMware(
阅读全文注:本文翻译自 Plerion 的文章《"But without PassRole it should be fine", Lambda edition》[1],可点击文末“阅读原文”按钮查看英文原
阅读全文注:本文翻译自 Juliet Security Team 的文章《Introducing the ABOM: Why Your CI/CD Pipelines Need a Bill of Mate
阅读全文注:本文翻译自de Março[1]的文章《Anatomia de um Infostealer Moderno: Três Camadas, Uma Botnet》[2],可点击文末“阅读原文”按
阅读全文注:本文翻译自 GMO Flatt Security 的文章《Remote Command Execution in Google Cloud with Single Directory Delet
阅读全文注:本文翻译自 Elastic Security Labs的文章《Linux & Cloud Detection Engineering - TeamPCP Container Attack Sce
阅读全文注:本文翻译自Apaksh[1]的文章《AWS Security Hardening: The Checklist Your Cloud Needs》[2],可点击文末“阅读原文”按钮查看英文原文。
阅读全文注:本文翻译自 Qualys 的文章《CrackArmor: Multiple vulnerabilities in AppArmor》[1],可点击文末“阅读原文”按钮查看英文原文。全文如下:摘要
阅读全文注:本文翻译自 Cymulate 的文章《CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation
阅读全文注:本文翻译自 Innora 的文章《Anatomy of a Cloud Cryptojacking Campaign: XMRig via Hetzner Rescue Mode with Mu
阅读全文注:本文翻译自 Daze Security 的文章《Azure DevOps Privilege Escalation via OIDC Abuse》[1],可点击文末“阅读原文”按钮查看英文原文。
阅读全文注:本文翻译自 Calif[1] 的文章《A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets》[2],可点
阅读全文注:本文翻译自 Microsoft 的文章《OAuth redirection abuse enables phishing and malware delivery》[1],可点击文末“阅读原文”
阅读全文注:本文翻译自 StepSecurity 的文章《hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Mic
阅读全文开源工具地址:https://github.com/BishopFox/cloudfox注:本文翻译自Bishop Fox的文章《Introducing CloudFox GCP: Attack P
阅读全文注:本文翻译自 Riptides 的文章《Secretless Azure access with tokenex: Federated Identity via User-Assigned Man
阅读全文