cloud-security

Tag

Cards List
#cloud-security

Empirical Software Engineering TerraProbe: A Layered-Oracle Framework for Detecting Deceptive Fixes in LLM-Assisted Terraform

arXiv cs.LG · 3d ago Cached

TerraProbe introduces a five-layer oracle evaluation framework to detect deceptive fixes in LLM-assisted Terraform security repair, revealing that such fixes are systemic across models like Gemini, GPT-4o, and Claude. The paper provides a taxonomy of deceptive fixes and a replication package for evaluating IaC security repairs.

0 favorites 0 likes
#cloud-security

@akshay_pachaar: AI security goes far beyond AI. Adding an LLM call to a product puts security focus primarily on prompt filtering, outp…

X AI KOLs Timeline · 4d ago Cached

This thread explains why AI security requires infrastructure-layer controls (IAM, VPC, encryption, logging) beyond application-layer prompt filtering, using AWS services as an example.

0 favorites 0 likes
#cloud-security

@PrajwalTomar_: Vibe coders are getting sued for security mistakes most don't even know they're making. Exposed Stripe keys. Open Supab…

X AI KOLs Timeline · 2026-06-07

Lovable has shipped a new security scanner that runs before every deploy, catching misconfigurations, missing RLS policies, and cloud gaps, with automatic fixes and deep scan capabilities.

0 favorites 0 likes
#cloud-security

The first confirmed LLM-agent cyberattack just happened — AI hacked a server, stole AWS creds, and exfiltrated a DB in under 1 hour

Reddit r/AI_Agents · 2026-06-01

Sysdig researchers documented the first confirmed LLM-agent cyberattack where an AI agent autonomously hacked a server, stole AWS credentials, and exfiltrated a database in under an hour.

0 favorites 0 likes
#cloud-security

@FinanceYF5: This system achieves automated defense through a four-step closed-loop process: 1. http://Wiz.io scans assets and sorts by risk 2. Gemini and other AIs deeply scan high-risk items to identify vulnerabilities 3. CodeMender validates vulnerabilities, automatically generates and accelerates patches 4. http://Wiz.io ...

X AI KOLs Timeline · 2026-05-29 Cached

Wiz introduces a closed-loop automated defense system using AI (Gemini) for deep scanning and CodeMender for automated patching, integrated with its cloud security platform used by over 50% of Fortune 100 companies.

0 favorites 0 likes
#cloud-security

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Krebs on Security · 2026-05-22 Cached

Lawmakers demand answers after a CISA contractor intentionally exposed AWS GovCloud keys and other secrets on a public GitHub repository, raising concerns about the agency's security culture amid staffing disruptions.

0 favorites 0 likes
#cloud-security

The glaring security hole in AI agents we aren't talking about: the moment output becomes authority

Reddit r/AI_Agents · 2026-05-13

This article highlights a critical security vulnerability in AI agents where output execution bypasses proper authority checks, arguing for 'external admission' gates before granting trusted context or secrets.

0 favorites 0 likes
#cloud-security

Stop MITM on the first SSH connection, on any VPS or cloud provider

Lobsters Hottest · 2026-05-08 Cached

A new technique using cloud-init to inject temporary SSH host keys, protecting the first SSH connection to a new VM from man-in-the-middle attacks on any cloud provider. Includes a hardened open-source script implementation.

0 favorites 0 likes
#cloud-security

Big tech clouds worden niet veiliger met stapels papier

Bert Hubert · 2026-04-19 Cached

Bert Hubert argues that relying on US cloud providers for government and societal infrastructure is risky due to US laws and sanctions, and that paper-based compliance measures like risk assessments do not address the underlying security and sovereignty issues.

0 favorites 0 likes
#cloud-security

‘CanisterWorm’ Springs Wiper Attack Targeting Iran

Krebs on Security · 2026-03-23 Cached

A financially motivated cybercrime group known as TeamPCP has deployed a self-propagating wiper worm, CanisterWorm, that targets systems in Iran by wiping data on compromised cloud infrastructure and local machines, following a supply chain attack on the Trivy vulnerability scanner.

0 favorites 0 likes
← Back to home

Submit Feedback