Cloud Security · 35 articles

Cloud Security

AWS, Azure, GCP, Kubernetes — IAM, posture, hardening, audits.

Cloud Security

GitHub Actions Supply Chain Attacks: How CI/CD Pipelines Became the New Target

Software supply chain attacks via CI/CD pipelines have moved from headline-grabbing incidents to a reliable, repeatable attack category. The pattern has evolved…

Jun 18, 2026 · 2 min read
Cloud Security

Cloud Control-Plane Attacks: The 2026 Post-Breach Playbook That Kills Your Logging

After initial access, 2026 attackers pivot to your cloud control plane: minting IAM persistence and killing CloudTrail logging. Here is the kill…

Jun 17, 2026 · 9 min read
Cloud Security

Zero Trust India 2026: A Practical Roadmap for Enterprises

A phased, vendor-neutral zero trust roadmap for Indian enterprises in 2026, mapped to DPDP, RBI and SEBI expectations.

Jun 16, 2026 · 6 min read
Cloud Security

SSRF in 2026: Cloud Metadata, IMDSv2 Bypasses, and Real Impact

SSRF plus cloud metadata equals stolen credentials. Why it still works in 2026 — and how IMDSv2 changes the game.

May 25, 2026 · 1 min read
Cloud Security

VAPT in CI/CD: Shifting Penetration Testing Left in 2026

You deploy daily; annual VAPT tests a snapshot that no longer exists. Here is how to shift testing into the pipeline.

May 25, 2026 · 1 min read
Cloud Security

Cloud Misconfigurations: The 60% Problem (IAM, Storage, Keys, Gateways)

Most cloud breaches are not exotic — they are misconfigurations. The 60% problem, and the checks to fix it.

May 25, 2026 · 1 min read
Cloud Security

AWS IAM Privilege Escalation: Real Attack Paths and How to Find Them

In AWS, identity is the perimeter — and IAM privesc is how attackers take the account. The paths to hunt for.

May 25, 2026 · 1 min read
Cloud Security

Kubernetes Penetration Testing: An Attacker’s Methodology for 2026

Modern attackers know RBAC, tokens, and admission control. Here is the Kubernetes pentest methodology, with commands.

May 25, 2026 · 1 min read
Cloud Security

Building Zero-Trust on Kubernetes: SPIFFE, mTLS, and Service Mesh in Practice

Architectural deep-dive on Kubernetes zero-trust. SPIFFE/SPIRE workload identity, mTLS at the pod boundary, Cilium L7 policy, and Kyverno admission enforcement.

May 22, 2026 · 8 min read
Cloud Security

Post-Quantum Cryptography Migration: Engineering Guide for 2026

A practitioner roadmap for PQC migration. NIST ML-KEM, ML-DSA, hybrid TLS, crypto-agility, CBOM, and a defensible 24-month plan for Indian enterprises.

May 22, 2026 · 8 min read