Endpoint Protection

A collection of 12 posts

AWS S3 Bucket Security: Find the Secrets Hiding Outside Git

AWS S3 Bucket Security: Find the Secrets Hiding Outside Git

S3 buckets have quietly become a credential blind spot: years of logs, backups, and pipeline output that nobody ever scans for secrets. In one 2025 incident (Sysdig), attackers reached admin access in eight minutes using IAM keys found in a public bucket.

Agentic AI Security: Credentials and Permissions Define the Blast Radius

Agentic AI Security: Credentials and Permissions Define the Blast Radius

* The trick matters less than the access. Three 2026 disclosures, GitLost, Claude Code's CVE-2026-21852, and Amazon Q's CVE-2026-12957, show agent manipulation determines less damage than the credentials and permissions the agent can reach. * Secrets exposure keeps