• Amazon S3 encrypts by default and The CircleCI Breach

  • Jan 14 2023
  • Length: 6 mins
  • Podcast

Amazon S3 encrypts by default and The CircleCI Breach

  • Summary

  • Cloud Security News this week 14 Jan 2023

    To read more about this week's stories head to https://cloudsecuritypodcast.tv/cloud-security-news/

    Podcast Twitter - Cloud Security Podcast (@CloudSecPod) Instagram - Cloud Security News 

    • According to recent study published by IEEE which I found interesting (which is the Institute of Electrical and Electronics Engineers around since 1963 apparently), “cloud computing (40%), 5G (38%), metaverse (37%), electric vehicles (EVs) (35%), and the Industrial Internet of Things (IIoT) (33%) will be the five most important areas of technology of 2023”
    • Late December, a security engineer at CircleCI received an email notification about a potential attack on his CircleCI account thanks to an AWS CanaryToken placed by him. On Jan 4th, CircleCI advised to rotate any and all secrets stored in CircleCI and published a blog outlining the various ways to do it. 
    • AWS announced on 5 Jan 2023, that Amazon S3 will now automatically apply server-side encryption for each new object. This has been welcomed by AWS users as a good compliance tick and also would assist with those pesky S3 bucket breaches which are still all too common.
    • Unit 42 researchers from Palo Alto Networks recently released a report about Automated Libra, the cloud threat actor behind the freejacking campaign PurpleUrchin, reporting that they had created more than 130,000 accounts on free or limited-use cloud platforms such as Heroku and GitHub.
    • Google has released reports sharing that API endpoints are increasing under attack mostly (no surprises here) due to API misconfigurations. According to their reports, many companies are intending to expand their real-time monitoring of API servers and using (AI/ML) systems to better discover flaws and detect attacks.
    Show More Show Less
activate_Holiday_promo_in_buybox_DT_T2

What listeners say about Amazon S3 encrypts by default and The CircleCI Breach

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.