Andoni A.
@andoniaf.unicrons.cloud
📤 35
📥 49
📝 32
Cloud Security Engineer. Writing about cloud security at unicrons.cloud.
It's funny because blameless culture applies to AI too. AI can make mistakes, but it's going to be your organization's lack of planning/monitoring/operational capabilities that causes "the incident".
add a skeleton here at some point
2 days ago
0
1
0
reposted by
Andoni A.
Corey Quinn
3 months ago
Whoa, this seems like a hell of a re:invent announcement that leaked too early:
www.youtube.com/watch?v=Q2Zp...
7
45
7
reposted by
Andoni A.
AWS User Group Sevilla (Spain)
5 months ago
🚀 ¡Nuevo meetup del AWS User Group Sevilla! Este mes hablamos de seguridad en la nube con AWS 🔐 y de cómo Prowler ayuda a auditar y reforzar tus cuentas AWS. 📅 29 oct, 19:00h · 📍Espacio RES 👉
www.meetup.com/aws-user-gro...
#AWS
#CloudSecurity
#Prowler
#Sevilla
0
5
4
reposted by
Andoni A.
Karen Haberkorn
6 months ago
Thanks to folks including
@frichetten.com
for feedback about our Bedrock API key launch. We're listening. Yesterday, we updated Bedrock and IAM docs (see
docs.aws.amazon.com/bedrock/late...
) to clarify that these are service-specific credentials and how to prevent their use in your environment. 1/2
add a skeleton here at some point
1
6
2
reposted by
Andoni A.
unicrons.cloud
6 months ago
And we couldn't let August end without publishing our writeups for the
@cloudvillage-dc.bsky.social
CTF at
@defcon.bsky.social
unicrons.cloud/en/2025/08/3...
loading . . .
WriteUp: Cloud Village CTF DEFCON 33 - unicrons.cloud
https://unicrons.cloud/en/2025/08/31/writeup-cloud-village-ctf-defcon-33/
0
1
1
reposted by
Andoni A.
unicrons.cloud
6 months ago
Wiz already released the new challenge for this month, so it is time to show how we solved the previous one! We always wanted to dig more about containers escaping, so it was a perfect opportunity to learn.
unicrons.cloud/en/2025/08/1...
loading . . .
WriteUp: Cloud Security Championship #2 - Contain Me If You Can - unicrons.cloud
https://unicrons.cloud/en/2025/08/15/writeup-cloud-security-championship-2---contain-me-if-you-can/
0
1
2
reposted by
Andoni A.
Nick Frichette
6 months ago
Major shout out to
@andoniaf.unicrons.cloud
for adding three new privilege escalation techniques to the Hacking the Cloud catalog! Contributions like this make everything possible.
hackingthe.cloud/aws/exploita...
loading . . .
AWS IAM Privilege Escalation Techniques - Hacking The Cloud
Common techniques that can be leveraged to escalate privileges in an AWS account.
https://hackingthe.cloud/aws/exploitation/iam_privilege_escalation/
0
8
2
Do you want to build "the perfect pipeline"? @Paco_S and I will present "Level Up Your CI/CD: Building a secure pipeline with OSS" workshop at
@cloudvillage-dc.bsky.social
@defcon.bsky.social
🚀
7 months ago
0
0
0
reposted by
Andoni A.
unicrons.cloud
8 months ago
We're at
@fwdcloudsec.org
and we have stickers. I do not know what else to say so just find us (or the stickers we left around 😂)
1
0
2
reposted by
Andoni A.
AWS User Group Valencia
9 months ago
Is your boss telling you to reduce the bill? Then this meetup is perfect for you! FinOps for Engineers: How to create real impact in your organization 💸 with Ernesto Suarez, CEO at @GlassityStartup 🗓Thu, June 12 ⏰18:30h 📍@FlywireEng office 📝RSVP:
www.meetup.com/aws-valencia...
loading . . .
FinOps for Engineers: How to create real impact in your organization, Thu, Jun 12, 2025, 6:30 PM | Meetup
**Talk: "FinOps for Engineers: How to create real impact in your organization"** Learn about FinOps culture from the engineering point of view and how to create a positive
https://www.meetup.com/aws-valencia/events/308390018/
0
1
2
An AWS Documentation Change Tracker, cool 👏🏻
awssecuritychanges.com
loading . . .
AWS Security Changes
https://awssecuritychanges.com/
10 months ago
1
3
0
Friendly reminder: IMDSv2 was released in November 2019.
www.bleepingcomputer.com/news/securit...
loading . . .
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials
A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extract EC2 Metadata, which could include Identity and Access Management (IA...
https://www.bleepingcomputer.com/news/security/hackers-target-ssrf-bugs-in-ec2-hosted-sites-to-steal-aws-credentials/amp/
10 months ago
1
1
1
"100% serverless Certificate Authority on AWS, only $50/year" Never thought I would hear all these words together😅 But it's true, go check this amazing project
serverlessca.com
by @paulschwarzen
loading . . .
Serverless CA on AWS
Serverless CA in AWS with FIPS 140-2 level 3 CA key storage and cost typically under $5 per month
https://serverlessca.com/
11 months ago
1
1
0
Vaya, parece que @colibid también retransmite partidos de futbol de forma "ilegal"...
11 months ago
0
0
0
"Vibe coders" are in trouble...
www.pillar.security/blog/new-vul...
loading . . .
New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents
https://www.pillar.security/blog/new-vulnerability-in-github-copilot-and-cursor-how-hackers-can-weaponize-code-agents
11 months ago
0
0
0
En casa del herrero, cuchillo de palo. 😅
medium.com/@adan.alvare...
loading . . .
GitHub Actions and the Pinning Problem: What 100 Security Projects Reveal
Only 7/100 popular security projects pin everything. Here’s what I learned digging into the data.
https://medium.com/@adan.alvarez/github-actions-and-the-pinning-problem-what-100-security-projects-reveal-54a3a9dcc902
11 months ago
0
0
0
Open Cloud Security agenda is out! 🎉
opencloudsecurity.vfairs.com/en/#agenda
loading . . .
Open Cloud Security Conference
https://opencloudsecurity.vfairs.com/en/#agenda
11 months ago
0
0
0
AWS Root Keys in Front-End Code?! Wtf 🙃
trufflesecurity.com/blog/researc...
loading . . .
Research finds 12,000 ‘Live’ API Keys and Passwords in DeepSeek's Training Data ◆ Truffle Security Co.
We scanned Common Crawl - a massive dataset used to train LLMs like DeepSeek - and found ~12,000 hardcoded live API keys and passwords. This highlights a growing issue: LLMs trained on insecure code m...
https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data
11 months ago
0
2
0
groundedcloudsecurity.substack.com/p/vulnerabil...
loading . . .
Cloud vulnerability teardown: what's important and what you can ignore
Breaking down the challenges of vulnerabilities in the cloud and how to identify if your team is at risk
https://groundedcloudsecurity.substack.com/p/vulnerability-management-but-in-the
11 months ago
0
2
0
reposted by
Andoni A.
Charity Majors
12 months ago
Psychological safety is NOT about lack of disagreement. Psychological safety REQUIRES: * disagreement and debate * setting standards for behavior and performance, and enforcing them * telling people things they don't want to hear * courage, from the bottom up * humility, from the top down
add a skeleton here at some point
8
270
79
www.anvilogic.com/report/2025-...
loading . . .
2025 State of Detection Engineering Report | Anvilogic
The 2025 State of Detection Engineering Report reveals key trends & challenges in detection engineering—from AI adoption to skill gaps and data access.
https://www.anvilogic.com/report/2025-state-of-detection-engineering
12 months ago
1
0
0
I've been accepted as Security AWS Community Builder 🎉 🎉 That means more AWS Cloud Security stuff is coming! 🙌
#AWSCommunity
12 months ago
0
4
0
Do you agree with this chatGPT definition of "misconfiguration" in a cloud security context? How would you define it?
12 months ago
1
0
1
reposted by
Andoni A.
Victor Grenu
12 months ago
Want to foster a cost-conscious culture in your DevOps team? We loved this Reddit post (300+ upvotes) about a startup cutting its cloud bill by 40% in weeks by fostering a culture of cost / waste awareness.
1
0
1
blog.ssojet.com/aws-iam-user...
loading . . .
AWS IAM User Enumeration Vulnerabilities: CVE-2025-0693 and Security Implications - SSOJet
Two critical username enumeration vulnerabilities were identified in the AWS Web Console, exposing all console-enabled Identity and Access Management (IAM) users to potential risk.
https://blog.ssojet.com/aws-iam-user-enumeration-vulnerabilities-cve-2025-0693-and-security-implications/
12 months ago
0
0
0
blog.toshokelectric.com/blog/how-muc...
"Industry has often landed on the terms “observability continuum” or “observability journey”, but let’s be clear: there are no endpoints (not observable/observable, start/end) here."
loading . . .
How much instrumentation is enough / when am I done? - Toshok's Musings
Short answer: never enough, never done <3
https://blog.toshokelectric.com/blog/how-much-is-enough/
about 1 year ago
1
0
0
reposted by
Andoni A.
AWS User Group Valencia
about 1 year ago
Couldn't make it to re:Invent last year? No problem, we've got you! 🤝 Viktor Vedmich, Senior Developer Advocate at AWS, is coming to Valencia with re:Invent re:Cap session. 🗓Wed, January 29 ⏰ 18:00h 📍 Flywire office 📝 RSVP:
t.co/Y7qmXreqjT
loading . . .
https://www.meetup.com/aws-valencia/events/305533795
https://t.co/Y7qmXreqjT
0
2
2
"@jcfarris.bsky.social's Three Laws of Cloud Security Auto Remediation" also known as "Please take into account this guardrails if you want to implement auto remediation without failing miserably"
www.chrisfarris.com/post/three-l...
loading . . .
Farris's Three Laws of Auto Remediation - Chris Farris
In this post, I present three laws of Cloud Security Robotics with homage to a SciFi great.
https://www.chrisfarris.com/post/three-laws/
about 1 year ago
0
1
0
reposted by
Andoni A.
Kathy Korevec
about 1 year ago
Making a giant mess then figuring out how to pick up the pieces might be the most efficient form of design out there.
softwaredoug.com/blog/2024/12...
loading . . .
Preferring throwaway code over design docs
If you have discipline to throw away your first idea, draft, throwaway PRs often drives more progress than a design doc.
https://softwaredoug.com/blog/2024/12/14/throwaway-prs-not-design-docs
2
21
7
reposted by
Andoni A.
over 1 year ago
El próximo miércoles 20 se lía parda en la meetup de Valencia DevOps. A partir de las 18:00 en las oficinas de Flywire. Descubre por qué Nix está transformando la manera en que gestionamos entornos y dependencias en el desarrollo de software
www.meetup.com/valencia-dev...
loading . . .
Nix en DevOps: entornos consistentes y reproducibles sin esfuerzo, Wed, Nov 20, 2024, 6:00 PM | Meetup
¡Únete a ValenciaDevOps y descubre por qué Nix está transformando la manera en que gestionamos entornos y dependencias en el desarrollo de software! En esta charla, Alberto
https://www.meetup.com/valencia-devops/events/304522322/?utm_medium=referral&utm_campaign=share-btn_savedevents_share_modal&utm_source=link
2
2
3
reposted by
Andoni A.
unicrons.cloud
over 1 year ago
You know us, if we see a scoreboard, there we go. And last weekend, we weren't at
#defcon32
, but we didn't miss the opportunity to participate in the @cloudvillage_dc CTF😬 Here we you have the 5 challenges we were able to solve:
https://unicrons.cloud/en/2024/08/13/writeup-cloud-village-ctf-2024/
loading . . .
WriteUp: Cloud Village CTF 2024 - unicrons.cloud
https://unicrons.cloud/en/2024/08/13/writeup-cloud-village-ctf-2024/
0
1
2
reposted by
Andoni A.
unicrons.cloud
over 1 year ago
It's been a while but the new episode of our IAM series is out! Let's talk about S3:
https://unicrons.cloud/en/2024/06/01/iam-policy-mishaps-case-1---s3/
loading . . .
IAM policy mishaps: Case 1 - S3 - unicrons.cloud
https://unicrons.cloud/en/2024/06/01/iam-policy-mishaps-case-1---s3/
1
1
3
"S3 decryption works more like access control than decryption." "Therefore s3 encryption can prevent data exfiltration but is irrelevant after exfiltration."
blog.plerion.com/s3-bucket-en...
loading . . .
S3 Bucket Encryption Doesn't Work The Way You Think It Works
Let's try all the different S3 encryption options, see why it's more like access control than encryption, and why that matters.
https://blog.plerion.com/s3-bucket-encryption-doesnt-work-the-way-you-think-it-works/?utm_source=cloudseclist.com&utm_medium=referral&utm_campaign=CloudSecList-issue-234
over 1 year ago
0
0
0
tldrsec.com/p/security-i...
over 1 year ago
0
1
0
reposted by
Andoni A.
unicrons.cloud
almost 2 years ago
We just launched
unicrons.cloud
. Check out our first blog post! IAM intro from our Sh3llCON talk, first episode of the series.
unicrons.cloud/en/2024/02/2...
loading . . .
IAM policy mishaps: Intro to IAM - unicrons.cloud
https://unicrons.cloud/en/2024/02/20/iam-policy-mishaps-intro-to-iam/
0
3
3
you reached the end!!
feeds!
log in