-
Continue reading →: Cloud Security Weekly Blog – Week 12
Amazon Supply chain security improved with package group in AWS codeArtifact. It can be applied against patterns like format, namespace and configure origin control (Allow or Block) of ingestion or publish new packages (Link) Across Cybersecurity Industry SonarQube is introducing SBOM Manager Fujitsu spills customer data (Data Leak) SQL Injection…
-
Continue reading →: Cloud Security Weekly News – Week 11GitHub repositories are used to Extract PII using information stealer called RisePro (Link) First, being ChatGPT allowing vulnerable / malicious plugin to be installed Second, 0 – click account takeover on plugin’s there by taking control of the account. Third, Similar to #2 , But manipulating OAuth Redirect. RCE on…
-
Continue reading →: Cloud Security Weekly News – Week 09
NIST 2 has been released officially (Link) , the draft version was already released and i also wrote a blog about it, I would recommend reading it If you would like to know changes with NIST 2(Link) Change HealthCare is under cyberattack for last 7 days due to Ransomware attack…
-
Continue reading →: Cloud Security Weekly News – Week 07
Azure Azure Firewall has improved its logs by having additional TCP handshake logs such as SYN-ACK, FIN, FIN-ACK, RST, and INVALID. Azure Firewall now can autoscale based on the number of connections apart from CPU usage and throughput. HSM used in Azure Keyvault has modernized by the availability of the…
-
Continue reading →: What is in NIST 2 Draft ?NIST Framework has been widely used across organization in different sectors. Now they have released NIST 2 Draft , Let’s see what they have Each organization have unique threats Vulnerabilities Risk Tolerance which results in different objectives and approach to the framework in managing the risk. This collectively creates the…
-
Continue reading →: Securing Artificial IntelligenceGoogle , AWS and Azure all are heavily investing in AI and enhancing their AI capability at a faster pace. So, as security personal how do you keep up with it? Today’s blog helps you to look Artificial intelligence from Application Security eyes. In Modern App architecture, i would include…
-
Continue reading →: Microsoft Identity Platform – Part 3
In Part 1 and Part2, we have been looking at the basics of identity (AuthN and AuthZ) and how SAML and OAuth work. Also, how OAuth 2.0 works in conjunction with OpenID Connect. This week let’s see different grant types of OAUTH 2.0. There are four types Authorization code Implicit…
-
Continue reading →: Microsoft Identity Platform – Part 2
Let’s see about OAuth with week! Lets assume we have a user and two websites (Website 1 and Website 2). User is trying to access website 2 via website 1 In Password Anti-pattern implementation website 1 stores/logs the user credentials . Resulting in insecure implementation. Website1 can now use user…
-
Continue reading →: Microsoft Identity Platform – Part 1
For next few weeks, I’ll go through MS Identity Platform and share how application can use the Platform to authenticate and authorize the users. Microsoft Identity platform components includes Authentication/Authorization services based on the industry standards OAuth 2.0 , OpenID Connect , SAML v2.0 and RBAC MSAL (Microsoft Authentication Library)…
-
Continue reading →: Implementing WAF in AzureThis week let’s see how to implement Azure WAF Why you need WAF ? One of the most vulnerable resources in your environment is the web Application that is internet-facing. It is an easy target for the actors as they can be easily accessed via Public URL. All they need…


