Teri Radichel's Avatar

Teri Radichel

@teriradichel

2nd Sight Lab. Cloud, SAAS, and App Pentesting. Security Research. AWS Security Hero . Author on Amazon. Former IANS, SANS faculty. GSE. Masters Software & Infosec.

1,204
Followers
125
Following
1,774
Posts
04.08.2023
Joined
Posts Following

Latest posts by Teri Radichel @teriradichel

Preview
Yubikey Push To Run A Lambda Function Leveraging a framework to kick off deterministic or AI agent batch jobs and workflows

Yubikey Push To Run A Lambda Function πŸ”’β˜οΈπŸ€– Leveraging a framework to kick off deterministic or AI agent batch jobs and workflows

teriradichel.substack.com/p/mfa-to-run...

07.03.2026 17:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Wondering why if Netgear is a US company when I go to login it is directing me to cognito-idp.eu-west-1.amazonaws.com

06.03.2026 18:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

They don’t always report issues that only affect a few customers. Also not sure if it was me or my network. We’ll see how it goes today.

06.03.2026 16:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Lexus Nexus Breach Involving AWS Secrets Manger, RDS, ECS Taking a look at the root cause of a breach on AWS, what is actually relevant, and how it may have been prevented

Lexus Nexus Breach Involving AWS Secrets Manger, RDS, ECS πŸ”’β˜οΈ

Taking a look at the root cause of a breach on AWS, what is actually relevant, and how it may have been prevented

teriradichel.substack.com/p/lexus-nexu...

06.03.2026 16:32 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Never underestimate the value of the OGs.

06.03.2026 07:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Took a look at the health dashboard and does not show anything is wrong,

But I did notice Amazon was down today due to deployment issue. Hmm.

06.03.2026 07:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I got the commands from Google aimode which was working fine. So I think it was something specific to AWS. I even turned off my firewall to try those actions *gasp* and did not work.

06.03.2026 07:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Other parts of AWS console were slow but working. Finally I just opened CloudShell and ran commands to stop all instances and verified stopped.

06.03.2026 07:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Looking at the network traffic I can see my browser is trying to reach sa regions when it should stay in us-east-x. I also saw us-west-2 and ca.

I also saw a bunch of denied traffic to sa GuardDuty and other domains with sa in them and the global console domain.

06.03.2026 07:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

For some reason I could not get to the AWS EC2 dashboard just now to stop an instance. I was trying over and over and looking at all the network traffic.

I had also just created a new account and could not add MFA to it. It kept rejecting my Yubikey. The screens looked different.

06.03.2026 07:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

This test cost me $75. I thought I had deleted all the resources the same day. Turns out I missed some in an alternate region.

05.03.2026 21:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m doing some testing here. I would *never* trust AI to deploy resources based on a prompt if I wasn’t researching something. Use AI to build deterministic scripts to deploy infrastructure on AWS. Then test and verify they work correctly before you use them in production.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Then it proceeded to set up an EC2 reserved instance associated with that service (yes really) in a region I wasn’t operating in.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I set up a script to deploy resources under a certain cost threshold. Turns out the AI intelligent brain thought it was good enough to just pick the first result in the price list for that service. Which was something cheap for a particular service.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

But rather than tell me that it’s not possible, I got back plausible results with a spot check. It never told me what I was requesting was not possible. It just gave me a script that does something related.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Next, I had AI write a script to calculate the cost of running any AWS command. You can’t. (I added to to my AWS wishlist on builder.aws.com)

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I think I told it to figure out and use the current region in the prompts. Can double check but will be creating a specific SCP for my lovely and creative agents.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I tested automatically creating some AWS infrastructure scripts and test them. Luckily I have an SCP set up to block all but there regions. It went off and created resources in all three regions.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

So here’s a couple of fun things I tried that show how counting on AI πŸ€– to do the right thing can go terribly wrong if you are not testing and paying attention.

05.03.2026 21:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I came to a lot of the same conclusions as most of the white papers I have read just by using AI with no complicated overhead, infrastructure, or wordiness. Link pinned to my profile. Good Vibes section of my blog.

05.03.2026 20:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Everyone is writing these complicated hard to read white papers about AI. πŸ€– If you’d rather get a quick rundown and understanding of how to use AI more effectively using a lot less words to explain check out my blog posts.

05.03.2026 20:55 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

If you don’t need AirPlay on your Mac OS I suggest disabling it.

05.03.2026 19:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
A Multi-Agent Workflow Creating a multi-agent workflow with Kiro CLI (or any other AI tool for that matter) that processes tasks efficiently

A Multi-Agent Workflow πŸ€–
Creating a multi-agent workflow with Kiro CLI (or any other AI tool for that matter) that processes tasks efficiently

teriradichel.substack.com/p/how-to-cre...

05.03.2026 16:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Just found out all my @Substack emails are being flagged as spam in some accounts even after the person adds the sender to the contact list and marks it as not spam. No idea how to resolve that but if you subscribe to my blog, check your spam folder.

04.03.2026 22:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I am currently performing API actions in S3 and getting network errors related to an Asia pacific region in the AWS console. What’s that all about?

04.03.2026 18:22 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
KISS Your AI Prompts Why you should reduce the complexity of your prompts

KISS Your AI Prompts πŸ€–
Why you should reduce the complexity of your prompts

teriradichel.substack.com/p/kiss-your-...

04.03.2026 17:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AWS Builder Center Connect with builders who understand your journey. Share solutions, influence AWS product development, and access useful content that accelerates your growth. Your community starts here.

I wish on AWS I could….

Add it to the #awswishlist

builder.aws.com/wishlist

04.03.2026 05:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Questions to ask when evaluating an authentication mechanism Why I still use a password with a Yubikey, not a passkey or a pin and dislike the device code flow with a browser

Questions to ask when evaluating an authentication mechanism πŸ”’

Why I still use a password with a Yubikey, not a passkey or a pin

Why I dislike device code flow with a browser

How lack of segregation facilitated a Microsoft breach.

Defense in Depth ⭐️

teriradichel.substack.com/p/questions-...

23.02.2026 15:27 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
OAuth redirection abuse enables phishing and malware delivery | Microsoft Security Blog OAuth redirection is being repurposed as a phishing delivery path. Trusted authentication flows are weaponized to move users from legitimate sign‑in pages to attacker‑controlled infrastructure.

OAuth redirection abuse enables phishing and malware delivery | Microsoft Security Blog

I just wrote about this type of attack and what you should be asking about authentication processes. Modifying scopes is an authorization issue but it’s related.

www.microsoft.com/en-us/securi...

03.03.2026 16:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Your Model Matters Recent experience trying to complete projects with different models

Your Model Matters πŸ€–
Recent experience trying to complete projects with different models

teriradichel.substack.com/p/your-model...

02.03.2026 16:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0