And we couldn't let August end without publishing our writeups for the @cloudvillage-dc.bsky.social CTF at @defcon.bsky.social
unicrons.cloud/en/2025/08/3...
And we couldn't let August end without publishing our writeups for the @cloudvillage-dc.bsky.social CTF at @defcon.bsky.social
unicrons.cloud/en/2025/08/3...
Wiz already released the new challenge for this month, so it is time to show how we solved the previous one!
We always wanted to dig more about containers escaping, so it was a perfect opportunity to learn.
unicrons.cloud/en/2025/08/1...
New post! π° WriteUp: Cloud Security Championship #1
unicrons.cloud/en/2025/07/0...
Probably you don't know how we look like so this is us
We're at @fwdcloudsec.org and we have stickers. I do not know what else to say so just find us (or the stickers we left around π)
Pensabais que nos habΓamos olvidado de la serie de IAM? Bueno, pues es correcto. PerdΓ³n por el retraso, pero aquΓ estamos de nuevo.
Hoy como estrella invitada: SNS βοΈ
unicrons.cloud/es/2025/02/2...
Did you think we had forgotten about the IAM series? Well, you were right. Sorry for the delay, but here we are again.
Today SNS as starring guest. βοΈ
unicrons.cloud/en/2025/02/2...
Do you agree with this chatGPT definition of "misconfiguration" in a cloud security context?
How would you define it?
The self described βShodan of AWSβ is now live! This is an amazing project from Daniel Grzelak that helps democratize cloud resource enumeration for the masses. Very excited about this!
awseye.com
In one hour we will be talking about Cloud Security in #AWSCommunityDaySpain π¬
PD: we have stickers... π¦
On our way to #AWSCommunityDaySpain π to talk about how to build your own CSPM with @steampipeio, AWS SecurityHub and AWS Organizations.
Do you have a tool that needs permissions across all your AWS accounts? Do you want to manage it using IaC? Check out our latest post! https://unicrons.cloud/en/2024/10/14/deploy-iam-roles-across-an-aws-organization-as-code/
Here we go! @fwdcloudsec
You know us, if we see a scoreboard, there we go. And last weekend, we weren't at #defcon32, but we didn't miss the opportunity to participate in the @cloudvillage_dc CTFπ¬
Here we you have the 5 challenges we were able to solve:
https://unicrons.cloud/en/2024/08/13/writeup-cloud-village-ctf-2024/
Y aquΓ tenΓ©is el enlace del feed en espaΓ±ol: https://unicrons.cloud/es/feed.xml
We have just enabled the RSS feed on our blog. You can subscribe here: https://unicrons.cloud/en/feed.xml
Because if you add an ARN as `Principal`, it must exists and will generate a unique ID. You can find more information in the following AWS docs, either way if someone can recreate your roles without your authorization, you have a bigger issue.
docs.aws.amazon.com/IAM/latest/U...
Extra bit we didn't include in the post: The source roles are included under the `aws:PrincipalArn` condition to avoid losing access if we recreate the roles. Why don't add them as `Principal`?
TambiΓ©n puedes leerlo en EspaΓ±ol aquΓ:
unicrons.cloud/es/2024/06/0...
It's been a while but the new episode of our IAM series is out! Let's talk about S3:
https://unicrons.cloud/en/2024/06/01/iam-policy-mishaps-case-1---s3/
TambiΓ©n puedes leerlo en EspaΓ±ol aquΓ
unicrons.cloud/es/2024/02/2...
We just launched unicrons.cloud. Check out our first blog post! IAM intro from our Sh3llCON talk, first episode of the series. unicrons.cloud/en/2024/02/2...