Cloud Security · 32 articles

Cloud Security

AWS, Azure, GCP, Kubernetes — IAM, posture, hardening, audits.

Cloud Security

Scenario Brief: How Post-Quantum TLS Could Roll Out Across UPI Infrastructure

Tabletop-ready forecast: an illustrative roadmap for ML-KEM-based hybrid TLS across UPI switch-to-issuer links and the CIO action plan around cryptography inventory.

May 22, 2026 · 2 min read
Cloud Security

Scenario Brief: Pod Escape via Cgroup Namespace TOCTOU — A Containerd Threat Model

Tabletop-ready scenario: a hypothetical containerd pod-escape via TOCTOU race. Why baseline Pod Security Admission is no longer enough and what to harden.

May 22, 2026 · 2 min read
Academy

Module 23 · Serverless Security — Functions, Event Sources, API Gateway

The serverless threat model What you no longer manage: OS patches, container runtime, network firewall (mostly). What becomes more critical: function code,…

May 14, 2026 · 3 min read
Academy

Module 21 · Cloud Workload Protection (CWPP) — VMs, Containers, Serverless

CWPP vs CSPM CSPM CWPP Configuration of cloud resources What is running on those resources Public buckets, broad SGs, unencrypted volumes Malware,…

May 14, 2026 · 2 min read
Academy

Module 22 · Kubernetes Security at Production Scale

The four production K8s domains Cluster security: API server, etcd, kubelet, control plane hardening. Workload security: Pod Security Standards, admission control, runtime…

May 14, 2026 · 3 min read
Academy

Module 19 · Cloud Security Posture Management (CSPM) at Production Scale

What CSPM tools do Connect to cloud accounts via API; continuously enumerate resources and configurations; check against benchmark rules; report findings. Tool…

May 14, 2026 · 3 min read
Academy

Module 20 · Securing Multi-Cloud Architectures

Why organisations go multi-cloud Resilience against single-provider outage. Regulator preference (RBI may prefer certain providers for specific workloads). Best-of-breed (Azure for M365…

May 14, 2026 · 3 min read
Academy

CASB and SaaS Data Governance

CASB modes (forward proxy, reverse proxy, API), SaaS-to-SaaS OAuth governance, shadow-IT discovery, sensitive-data inventory across 200+ SaaS apps, and the rollout pattern…

Apr 26, 2026 · 3 min read
Cloud Security

SSRF Beyond AWS: GCP, Azure, On-Prem and DNS Rebinding

SSRF attack surface beyond AWS metadata — GCP and Azure metadata endpoints, on-prem internal services (Redis, Elasticsearch, Kubernetes API), DNS rebinding bypass,…

Apr 25, 2026 · 4 min read
Cloud Security

Kubernetes Pentest: Top 10 Misconfigurations We Find in Indian Production

The 10 Kubernetes misconfigurations we routinely find — default ServiceAccount tokens, privileged containers, hostPath, broad RBAC, insecure API server, unencrypted etcd, no…

Apr 25, 2026 · 4 min read