-
Continue reading →: Cloud & AI Security – week 40
NVIDIA Open Agent Safety Platform: OpenShell + Sentry Today NVIDIA launched Open Agent Safety Platform , It is combination of the OpenShell software (first released in March 2026) and NVIDIA Sentry . OpenShell provides runtime to the agent while sentry (hardware reference design) provides out-of-band watchdog OpenShell OpenShell is a…
-
Continue reading →: Cloud & AI Security Blog – Week 39
Back to my blog after 7 months of hibernation. I’ve been stretching my brain on things that excited me, and still continue to excite me, but I felt it was time to get back to the blog. In future posts, I want to focus more on the why aspect .…
-
Continue reading →: Cloud Security Blog – Week 07AI Security There are two ways to tamper the model file [snip below] To mitigate the threat, traditional software security practices and malware scanning tools are the first line of defense With the discovery of CVE-2025-68664 highlights the importance of AI supply chain security WIZ discovers security threats in the…
-
Continue reading →: Cloud Security Blog – Week 50React2Shell [CVE-2025-55182 ] Affected components: React Server components in React 19.x and Next.js 15.x/16.x with App Router CVSS Score:10 Attack vector: Unauthenticated remote code execution Upgrade RSC Components should update to the latest patched versions 19.0.1, 19.1.2, and 19.2.1 and Next.js 15-16 with App Router should update to a patched version Using Custom WAF, I…
-
Continue reading →: Cloud Security Weekly Blog – Week 33Azure Private IP address only frontend IP configuration Elimination of inbound traffic from GatewayManager service tag via Network Security Group Ability to define a Deny All outbound Network Security Group (NSG) rule to restrict egress traffic to the Internet Ability to override the default route to the Internet (0.0.0.0/0) DNS resolution via…
-
Continue reading →: EchoLeak M365 Copilot Vulnerability
In this blog you learn about M365 copilot vulnerability. Zero-click attack chain results in compromising of Copilot data integrity High Level OWASP Top 10 Indirect prompt Injection Exploitation technique LLM Scope Violation Risk Data Exfiltration Vulnerabilities Bypassing XPIA Classifiers [AI Vulnerability] Bypassing external link Redaction [Traditional Vulnerability] Bypassing CSP [Traditional…
-
Continue reading →: Cloud Security Weekly blog – Week 39, 40AWS Security updates AWS announces general availability for Security Group Referencing on AWS Transit Gateway . Wondering what is Security Group , Security groups and network ACLs are similar in that they allow you to control access to AWS resources within your VPC. But security groups allow you to control…
-
Continue reading →: Cloud Security Weekly Blog – Week 38AWS Security updates AWS WAF Bot Control Managed Rule expands bot detection capabilities Azure Security updates (No Major updates) Security around the world OS command Injection in Ivanti Cloud Service Appliance versions (Link) Phishing Pages Delivered Through Refresh HTTP Response Header (Link) RCE Vulnerability in GCP is fixed (Link) OpenAI’s…
-
Continue reading →: Cloud Security Weekly Blog – Week 37Azure security updates Azure Bastion now supports Microsoft Entra ID authentication for SSH connections in the portal (Link) AWS security updates Customers can now access and manage their Network Firewalls privately, without going through the public internet (Link) Customer can create and manage your resource shares from within your Amazon…
-
Continue reading →: Cloud Security Weekly News – Week 36Azure Security Updates TLS 1.0 and 1.1 will be retiring on OCT 31st 2024 (Link) Azure WAF JS challenge in Azure Front Door (Link) Double encryption at-rest for Azure NetApp Files (Link) FIPS mutability support in AKS (Link) Azure Policy support for Azure Database for PostgreSQL – Flexible Server (Link)…