Andoni A.'s Avatar

Andoni A.

@andoniaf.unicrons.cloud

Cloud Security Engineer. Writing about cloud security at unicrons.cloud.

35
Followers
49
Following
32
Posts
15.10.2023
Joined
Posts Following

Latest posts by Andoni A. @andoniaf.unicrons.cloud

It's funny because blameless culture applies to AI too. AI can make mistakes, but it's going to be your organization's lack of planning/monitoring/operational capabilities that causes "the incident".

21.02.2026 08:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Whoa, this seems like a hell of a re:invent announcement that leaked too early:

www.youtube.com/watch?v=Q2Zp...

21.11.2025 04:09 πŸ‘ 45 πŸ” 6 πŸ’¬ 7 πŸ“Œ 1
Post image

πŸš€ Β‘Nuevo meetup del AWS User Group Sevilla!
Este mes hablamos de seguridad en la nube con AWS πŸ” y de cΓ³mo Prowler ayuda a auditar y reforzar tus cuentas AWS.
πŸ“… 29 oct, 19:00h Β· πŸ“Espacio RES
πŸ‘‰ www.meetup.com/aws-user-gro...

#AWS #CloudSecurity #Prowler #Sevilla

10.10.2025 11:44 πŸ‘ 5 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0

Thanks to folks including @frichetten.com for feedback about our Bedrock API key launch. We're listening. Yesterday, we updated Bedrock and IAM docs (see docs.aws.amazon.com/bedrock/late...) to clarify that these are service-specific credentials and how to prevent their use in your environment. 1/2

06.09.2025 00:39 πŸ‘ 6 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Post image

followed by this image from our workshop πŸ˜‚ github.com/unicrons/sec...

08.09.2025 12:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
WriteUp: Cloud Village CTF 2024 - unicrons.cloud

I always sent people this challenge from the Cloud Village CTF, so they understand how easy you can misconfigure OIDC unicrons.cloud/en/2024/08/1...

08.09.2025 12:37 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
WriteUp: Cloud Village CTF DEFCON 33 - unicrons.cloud

And we couldn't let August end without publishing our writeups for the @cloudvillage-dc.bsky.social CTF at @defcon.bsky.social

unicrons.cloud/en/2025/08/3...

31.08.2025 08:40 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
WriteUp: Cloud Security Championship #2 - Contain Me If You Can - unicrons.cloud

Wiz already released the new challenge for this month, so it is time to show how we solved the previous one!

We always wanted to dig more about containers escaping, so it was a perfect opportunity to learn.
unicrons.cloud/en/2025/08/1...

28.08.2025 19:34 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
AWS IAM Privilege Escalation Techniques - Hacking The Cloud Common techniques that can be leveraged to escalate privileges in an AWS account.

Major shout out to @andoniaf.unicrons.cloud for adding three new privilege escalation techniques to the Hacking the Cloud catalog! Contributions like this make everything possible.
hackingthe.cloud/aws/exploita...

21.08.2025 15:24 πŸ‘ 8 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Post image

Do you want to build "the perfect pipeline"?

@Paco_S and I will present "Level Up Your CI/CD: Building a secure pipeline with OSS" workshop at @cloudvillage-dc.bsky.social @defcon.bsky.social πŸš€

15.07.2025 11:08 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

We're at @fwdcloudsec.org and we have stickers. I do not know what else to say so just find us (or the stickers we left around πŸ˜‚)

30.06.2025 21:44 πŸ‘ 0 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Preview
FinOps for Engineers: How to create real impact in your organization, Thu, Jun 12, 2025, 6:30 PM | Meetup **Talk: "FinOps for Engineers: How to create real impact in your organization"** Learn about FinOps culture from the engineering point of view and how to create a positive

Is your boss telling you to reduce the bill? Then this meetup is perfect for you!

FinOps for Engineers: How to create real impact in your organization πŸ’Έ
with Ernesto Suarez, CEO at @GlassityStartup

πŸ—“Thu, June 12
⏰⁣18:30h
πŸ“@FlywireEng
office
πŸ“RSVP: www.meetup.com/aws-valencia...

09.06.2025 15:28 πŸ‘ 1 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
Introducing a New Way to Track AWS Documentation Changes | Miggo Introducing The New Way to Track AWS Documentation Changes

www.miggo.io/resources/in...

17.04.2025 06:31 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
AWS Security Changes

An AWS Documentation Change Tracker, cool πŸ‘πŸ»

awssecuritychanges.com

17.04.2025 06:31 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Capital One's $200M Cloud Data Breach
Capital One's $200M Cloud Data Breach YouTube video by Kevin Fang

Would you prefer a video? I also have a video. www.youtube.com/watch?v=r7HV...

14.04.2025 16:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Steal EC2 Metadata Credentials via SSRF - Hacking The Cloud Old faithful; How to steal IAM Role credentials from the EC2 Metadata service via SSRF.

Never heard about this? No problem.

Take a look to hackingthe.cloud/aws/exploita... to quickly understand how attackers do it.

And this github.com/ramimac/aws-... to understand how common (and old) this kind of attacks are.

14.04.2025 16:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extractΒ EC2 Metadata, which could includeΒ Identity and Access Management (IA...

Friendly reminder: IMDSv2 was released in November 2019.

www.bleepingcomputer.com/news/securit...

14.04.2025 16:09 πŸ‘ 1 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
How We Saved $70K/Year with an Open Source Private Cloud CA | Paul Schwarzenberger, Q-Solution
How We Saved $70K/Year with an Open Source Private Cloud CA | Paul Schwarzenberger, Q-Solution YouTube video by Prowler

The talk is already available in YT: www.youtube.com/watch?v=p2Cb...

11.04.2025 13:40 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Serverless CA on AWS Serverless CA in AWS with FIPS 140-2 level 3 CA key storage and cost typically under $5 per month

"100% serverless Certificate Authority on AWS, only $50/year"

Never thought I would hear all these words togetherπŸ˜…

But it's true, go check this amazing project serverlessca.com by @paulschwarzen

08.04.2025 17:54 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Vaya, parece que @colibid tambiΓ©n retransmite partidos de futbol de forma "ilegal"...

06.04.2025 14:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents

"Vibe coders" are in trouble...

www.pillar.security/blog/new-vul...

02.04.2025 07:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub Actions and the Pinning Problem: What 100 Security Projects Reveal Only 7/100 popular security projects pin everything. Here’s what I learned digging into the data.

En casa del herrero, cuchillo de palo. πŸ˜…

medium.com/@adan.alvare...

31.03.2025 06:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Open Cloud Security Conference

Open Cloud Security agenda is out! πŸŽ‰

opencloudsecurity.vfairs.com/en/#agenda

26.03.2025 17:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Research finds 12,000 β€˜Live’ API Keys and Passwords in DeepSeek's Training Data β—† Truffle Security Co. We scanned Common Crawl - a massive dataset used to train LLMs like DeepSeek - and found ~12,000 hardcoded live API keys and passwords. This highlights a growing issue: LLMs trained on insecure code m...

AWS Root Keys in Front-End Code?! Wtf πŸ™ƒ

trufflesecurity.com/blog/researc...

20.03.2025 09:41 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Cloud vulnerability teardown: what's important and what you can ignore Breaking down the challenges of vulnerabilities in the cloud and how to identify if your team is at risk

groundedcloudsecurity.substack.com/p/vulnerabil...

18.03.2025 09:17 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Psychological safety is NOT about lack of disagreement.

Psychological safety REQUIRES:

* disagreement and debate
* setting standards for behavior and performance, and enforcing them
* telling people things they don't want to hear
* courage, from the bottom up
* humility, from the top down

13.03.2025 23:06 πŸ‘ 271 πŸ” 73 πŸ’¬ 8 πŸ“Œ 6
Post image
10.03.2025 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Key takeaways for me:
- "False Positives Rate" as the most important metric for measuring detection eng. success
- "Most detections (42%) were custom-built to fit their organization’s unique envs. Vendor-provided come in second at 37%, but few rely on them exclusively."

10.03.2025 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
2025 State of Detection Engineering Report | Anvilogic The 2025 State of Detection Engineering Report reveals key trends & challenges in detection engineeringβ€”from AI adoption to skill gaps and data access.

www.anvilogic.com/report/2025-...

10.03.2025 10:57 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0