Cloud Security Partners Blog Cloud Security Partners Blog
  • Website
  • News
  • About
  • Twitter
  • LinkedIn
Sign in Subscribe
Don't let your containers escape! Update runc & Docker Now!

Don't let your containers escape! Update runc & Docker Now!

TL;DR: Update runc and associated software (such as Docker) to the latest version to address several container breakout vulnerabilities. The security research team at Snyk recently disclosed vulnerabilities in runc <= 1.11.11, which can result in container escapes. Container escaping allows for access to the host operating
CSP Team Feb 1, 2024
Upcoming Events at CSP!

Upcoming Events at CSP!

We're starting off the year with a few big events we're speaking and training at. Get ready for a deep dive into the latest in cloud computing and cybersecurity with our very own experts, Mike McCabe and John Poulin. Mike McCabe at Cloud Connect - DeveloperWeek
Mike McCabe Jan 29, 2024
OIDC for GitHub Actions

OIDC for GitHub Actions

At Cloud Security Partners, we perform a lot of code reviews and Cloud Security Assessments. During these engagements, we see many different CI/CD patterns that cause us to raise our eyebrows. One situation in particular that we encounter relatively often is the unsafe use of AWS credentials. The CIS
CSP Team Jan 25, 2024
Our Support For Cloudsplaining

Our Support For Cloudsplaining

We’re proud to announce that Cloud Security Partners will be forking and maintaining Cloudsplaining, the popular cloud IAM tool. Open source and giving back to the community are very important to us and something we try to do often via contributions and free training! The cloud security community has
Mike McCabe Jan 16, 2024
Gen AI Security: An Introduction and Resource Guide

Gen AI Security: An Introduction and Resource Guide

Like many industries, Artificial Intelligence has taken the security industry by storm. Security practitioners now are faced with the challenge of understanding new classifications of threats and new techniques of attack. Threat Actors are utilizing AI to improve their attacks, while also exploiting AI services. AI and Generative AI utilize
Mike McCabe Dec 14, 2023
LASCON Recap - Infrastructure as Code

LASCON Recap - Infrastructure as Code

Recently, we had the privilege of participating in and sponsoring the Lonestar Application Security Conference (LASCON). Our CEO, Michael McCabe, and Ken Toler delivered a training session and a talk on exploiting Terraform for remote code execution; both received a fantastic turnout. In between operating our booth, we had the
CSP Team Nov 6, 2023
RDS Revealed? Time to Give It Some Shade!

RDS Revealed? Time to Give It Some Shade!

By: John Poulin At Cloud Security Partners, we have audited thousands of customer AWS accounts as part of our security reviews. Across our customers, roughly 5% of the AWS Relational Database Service (RDS) instances we analyze are publicly accessible. A general rule of thumb across the security industry is that
CSP Team Oct 16, 2023

Subscribe to Cloud Security Partners Blog

Don't miss out on the latest news. Sign up now to get access to the library of members-only articles.
Cloud Security Partners Blog © 2025.