Cloud Security · 32 articles

Cloud Security

AWS, Azure, GCP, Kubernetes — IAM, posture, hardening, audits.

Cloud Security

SSRF in 2026: Cloud Metadata, IMDSv2 Bypasses, and Real Impact

SSRF plus cloud metadata equals stolen credentials. Why it still works in 2026 — and how IMDSv2 changes the game.

May 25, 2026 · 1 min read
Cloud Security

VAPT in CI/CD: Shifting Penetration Testing Left in 2026

You deploy daily; annual VAPT tests a snapshot that no longer exists. Here is how to shift testing into the pipeline.

May 25, 2026 · 1 min read
Cloud Security

Cloud Misconfigurations: The 60% Problem (IAM, Storage, Keys, Gateways)

Most cloud breaches are not exotic — they are misconfigurations. The 60% problem, and the checks to fix it.

May 25, 2026 · 1 min read
Cloud Security

AWS IAM Privilege Escalation: Real Attack Paths and How to Find Them

In AWS, identity is the perimeter — and IAM privesc is how attackers take the account. The paths to hunt for.

May 25, 2026 · 1 min read
Cloud Security

Kubernetes Penetration Testing: An Attacker’s Methodology for 2026

Modern attackers know RBAC, tokens, and admission control. Here is the Kubernetes pentest methodology, with commands.

May 25, 2026 · 1 min read
Cloud Security

Building Zero-Trust on Kubernetes: SPIFFE, mTLS, and Service Mesh in Practice

Architectural deep-dive on Kubernetes zero-trust. SPIFFE/SPIRE workload identity, mTLS at the pod boundary, Cilium L7 policy, and Kyverno admission enforcement.

May 22, 2026 · 8 min read
Cloud Security

Post-Quantum Cryptography Migration: Engineering Guide for 2026

A practitioner roadmap for PQC migration. NIST ML-KEM, ML-DSA, hybrid TLS, crypto-agility, CBOM, and a defensible 24-month plan for Indian enterprises.

May 22, 2026 · 8 min read
Cloud Security

Cloud Detection and Response for AWS: Threat Hunting Playbook for 2026

A practitioner playbook for AWS CDR. CloudTrail rules, GuardDuty triage, three end-to-end response playbooks, and the telemetry stack Indian SOCs need.

May 22, 2026 · 7 min read
Cloud Security

SBOM Operations at Enterprise Scale: CycloneDX, SPDX, and SLSA Provenance

Moving from SBOM generation to SBOM operations. Dependency-Track, reachability, VEX, SLSA Build L3, vendor SBOM intake, and a maturity model for grading…

May 22, 2026 · 8 min read
Cloud Security

Kubernetes Pod Security in Production: PSA, Kyverno, and OPA Gatekeeper Compared

Comparative analysis of the three dominant Kubernetes policy engines. When to use which, how to compose them, and a defensible migration from…

May 22, 2026 · 9 min read