Cloudflare zero-day: Accessing any host globally
https://fearsoff.org/research/cloudflare-acme
#HackerNews #Cloudflare #ZeroDay #CloudSecurity #CyberThreats #Vulnerability #Research #AccessControl
Cloudflare zero-day: Accessing any host globally
https://fearsoff.org/research/cloudflare-acme
#HackerNews #Cloudflare #ZeroDay #CloudSecurity #CyberThreats #Vulnerability #Research #AccessControl
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
#HackerNews #SupplyChainVulnerability #AWS #GitHub #Repos #AWSConsole #CyberSecurity #CloudSecurity
Surprise, surprise! US-Behörden können auf europäische Cloud-Daten zugreifen...Das bisher unveröffentlichte Rechtsgutachten der Uni Köln, erstellt im Auftrag des Bundesinnenministeriums, wurde jetzt durch eine Anfrage nach dem Informationsfreiheitsgesetz öffentlich.
Zum Artikel: https://heise.de/-11111043?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#DigitaleSouveränität #Datenschutz #CloudSecurity #DSGVO #Cybersicherheit
Surprise, surprise! US-Behörden können auf europäische Cloud-Daten zugreifen...Das bisher unveröffentlichte Rechtsgutachten der Uni Köln, erstellt im Auftrag des Bundesinnenministeriums, wurde jetzt durch eine Anfrage nach dem Informationsfreiheitsgesetz öffentlich.
Zum Artikel: https://heise.de/-11111043?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#DigitaleSouveränität #Datenschutz #CloudSecurity #DSGVO #Cybersicherheit
★ Do you get excited or upset about AWS SCPs, or GCP Org Policies?
★ Do you have experience developing software to solve cloud security challenges?
★ Do you downplay your cloud security knowledge but actually you know a lot of niche oddities of cloud IAM?
★ Do you like working in diverse security teams that care about your wellbeing?
★ Do you want to get paid to work on cloud security for one of the most sophisticated AWS environments in the world?
I'm hiring an L5 (mid-late career) cloud security software engineer for Netflix Cloud Security! I'm looking for someone with skills across cloud security, cloud infra, AND software engineering, and would like to see at least one of these skill areas:
• Experience building secure-by-default controls for Infra-as-Code (IAC) tools such as Terraform
• Experience building robust systems or easy to use abstractions for AWS native services such as EC2, Lambda, S3, SNS, SQS, DDB, etc.
• Experience leveraging AWS Config, Cloud Control API, CloudFormation, and CloudTrail
https://explore.jobs.netflix.net/careers/job/790304450320-security-software-engineer-l5-cloud-infrastructure-security-usa-remote
Netflix Cloud Security has industry-leading cloud security capabilities, and one of the most sophisticated AWS environments in the world. As a manager, I prioritize inclusion in order to maintain both the wellbeing and productivity of our diverse team. We hold folks to delivering high quality work by creating environments where you can operate to the best of your ability, through work-life balance, expecting folks to take ample time off (~6 weeks, but no one will track it). I'm happy to talk about this role and about how I manage teams — e.g., my Explicit Expectations and my commitments to my reports. https://managinginthemargins.com/explicit-expectations-leadership-by-example-edcb451abfb4
I'd love to hear what perspectives, skills, and experiences you could bring to our team! [This role can be US remote or office, with a distributed team across the US]
#Hiring #FediHire #CloudSecurity
📣 Huawei Cloud – Relance Europe Risk Watch
Nous avons publié une enquête complète sur LinkedIn et YouTube sur le risque fournisseur.
Toujours aucune réponse de Huawei Cloud Europe.
▶ Vidéo : https://youtu.be/TjnwDO9B3v0?si=ECqGoAfVXGN9Wf1g
L’Europe doit choisir : résilience ou risque.
Nous invitons @EUCommission à examiner ce cas.
#CyberSécurité #RisqueFournisseur #HuaweiCloud #EuropeRiskWatch #DGCONNECT
Hi @campuscodi,
We’re investigating Huawei Cloud’s terms of service and their implications for European data sovereignty.
Their customer agreement and compliance documents suggest Huawei retains the right to transfer personal data to servers in mainland China under certain conditions.
Given your expertise, we’d value your view:
Could this pose a systemic risk for EU-based organizations relying on Huawei Cloud?
#EuropeRiskWatch #CyberSecurity #DataSovereignty #HuaweiCloud #GDPR #CloudSecurity