CloudSec Wine
2.27K subscribers
1.13K photos
24 files
1.43K links
All about cloud security

Contacts:
@AMark0f
@dvyakimov

About DevSecOps:
@sec_devops
Download Telegram
🤖 OpenAI's Defense Factory

OpenAI's Defense Factory is a continuous, agent-first vulnerability detection and remediation pipeline using Codex and specialized cyber models (Daybreak Blue/Red). It automates inventory, triage, dynamic validation, ownership assignment, and verified patching, achieving 0.81% false-positive rate and 0.53% fix rollback rate.

https://openai.com/ru-RU/the-defense-factory

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
🤖 Hacking AI customer service agents

Techniques for attacking AI customer service agents: email spoofing to hijack agent actions, MFA bypass via email normalization and IVR channel-switching, email address smuggling via RFC comments for IDOR, OTP exfiltration via inbox-monitoring agents, asymmetric MIME content, conversation forgery, and RAG knowledge base poisoning.

https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
🤖 DeepSeek Harness Vulnerability. Lets AI Agents Escape Their Own Sandbox

CVE-2026-82533 (CVSS 9.4) in DeepSeek Harness lets a sandboxed AI agent escape confinement via a single curl call to the unauthenticated local API, spoofing the Host header to elevate its session to danger-full-access.

https://www.ox.security/blog/cve-2026-82533-deepseek-harness-ai-agent-sandbox-escape

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
🔶 Introducing Amazon EBS Volume Clones across AWS account

AWS introduces Amazon EBS Volume Clones with cross-account copy, so you can create copies of your EBS volumes into other AWS accounts and optionally re-encrypt them with an AWS Key Management Service (AWS KMS) key in the target account.

https://aws.amazon.com/ru/blogs/aws/introducing-amazon-ebs-volume-clones-across-aws-accounts

#aws
❤1👍1🔥1
🤖 Containers Are No Longer a Security Boundary

AI-accelerated kernel vuln discovery (5,976 CVEs in 2026) has made container escapes trivial. CVE-2026-80521, a Linux AF_UNIX use-after-free, demonstrates a full container escape.

https://depthfirst.com/research/containers-are-no-longer-safe

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
👩‍💻 How to secure edge AI in customer-owned environments

Edge AI shifts trust responsibility to customers who operate more of the AI stack outside provider control. Organizations must verify runtimes via attestation, validate AI artifact provenance, constrain model actions through deterministic mediation, and bind sensitive assets only to trusted, evidence-verified environments.

https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments

#azure
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1
🤖 Hacking OpenAI

Researchers chained a libheif heap buffer overflow (via Discourse/ImageMagick image upload) with an OpenAI SSO misconfiguration to achieve RCE on community.openai.com, take over employee ChatGPT/Codex accounts, and access OpenAI's internal GitHub monorepo.

https://www.hacktron.ai/blog/hacking-openai

#AI
Please open Telegram to view this post
VIEW IN TELEGRAM
👍2❤1🔥1
🔶 Exploring the new AWS Sign Up experience

This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.

https://www.wiz.io/blog/exploring-the-new-aws-sign-up-experience

#aws
❤1👍1🔥1
🔴 Strengthen your CI/CD pipeline with new Secure Source Manager capabilities

Google Cloud Secure Source Manager adds two GA features: a Code Owners system enabling per-file and per-branch PR approval governance with nestable CODEOWNERS files, and Developer Connect integration for private-network CI/CD connectivity using Private Service Connect and VPC Service Controls.

https://cloud.google.com/blog/products/identity-security/strengthen-your-cicd-pipeline-with-new-secure-source-manager-capabilities

#gcp
Please open Telegram to view this post
VIEW IN TELEGRAM
❤1👍1🔥1