Cloud Security Partners Blog Cloud Security Partners Blog
  • Website
  • News
  • About
  • Twitter
  • LinkedIn
Sign in Subscribe
Gen AI Security: An Introduction and Resource Guide

Gen AI Security: An Introduction and Resource Guide

Like many industries, Artificial Intelligence has taken the security industry by storm. Security practitioners now are faced with the challenge of understanding new classifications of threats and new techniques of attack. Threat Actors are utilizing AI to improve their attacks, while also exploiting AI services. AI and Generative AI utilize
Mike McCabe Dec 14, 2023
LASCON Recap - Infrastructure as Code

LASCON Recap - Infrastructure as Code

Recently, we had the privilege of participating in and sponsoring the Lonestar Application Security Conference (LASCON). Our CEO, Michael McCabe, and Ken Toler delivered a training session and a talk on exploiting Terraform for remote code execution; both received a fantastic turnout. In between operating our booth, we had the
CSP Team Nov 6, 2023
RDS Revealed? Time to Give It Some Shade!

RDS Revealed? Time to Give It Some Shade!

By: John Poulin At Cloud Security Partners, we have audited thousands of customer AWS accounts as part of our security reviews. Across our customers, roughly 5% of the AWS Relational Database Service (RDS) instances we analyze are publicly accessible. A general rule of thumb across the security industry is that
CSP Team Oct 16, 2023
The Security Absolutist

The Security Absolutist

All security practitioners know the Security Absolutist. It’s the practitioner who has a plan before the context, is unapologetic in their approach to security, and is unwaveringly confident in their solution. Seemingly always frustrated with the current state of security in business and consistently angry at why “people can’
Mike McCabe Oct 2, 2023
The Hidden Dangers of Using Terraform's Remote-Exec Provisioner

The Hidden Dangers of Using Terraform's Remote-Exec Provisioner

Terraform is a powerful infrastructure as code tool that can support multi-cloud deployments. Terraform provides consistent and reliable deployments for cloud infrastructure. But as with every tool there are hidden dangers built-in we need to check for! The remote-exec provisioner in Terraform can be a valuable tool, providing the ability
Mike McCabe Sep 13, 2023
SQL query written in Athena to query for specific log events.

Exploring Amazon Athena in Incident Response: A Practical Approach

Recently, our team was pulled into an incident response engagement. As part of the breach investigation, we needed to review months of extensive nginx log files stored on Amazon S3 to determine an application issue causing data leakage. Complicating matters, we had no access to our traditional SIEM tools, prompting
CSP Team Sep 7, 2023
Infrastructure as Code Security

Infrastructure as Code Security

I was excited to have the opportunity to speak recently at Kernelcon and BSidesNYC about one of my favorite topics, infrastructure as code (IAC). Having helped multiple companies build IAC security programs, talking about what we've learned is always enjoyable. Companies moving to centralized and well-managed infrastructure as
Mike McCabe May 1, 2023

Subscribe to Cloud Security Partners Blog

Don't miss out on the latest news. Sign up now to get access to the library of members-only articles.
Cloud Security Partners Blog © 2025.