First Action After Compromise: Blind the Audit
A developer detailed how attackers can blind AWS audit trails by calling `cloudtrail stop-logging`, which halts event delivery while leaving the trail's configuration looking healthy. The post highlig…
A developer detailed how attackers can blind AWS audit trails by calling `cloudtrail stop-logging`, which halts event delivery while leaving the trail's configuration looking healthy. The post highlig…
Stave, a cloud security firm, analyzed the CSA's Top Threats to Cloud Computing 2026 report and identified 112 machine-verifiable properties across all 11 threats, with 93 snapshot-verifiable and 91 a…
Stave, a security startup, introduced a new approach to prioritize cloud misconfiguration findings by evaluating compound attack paths rather than individual permissions. The system labels findings as…
The article describes Stave, a cloud-security tool that replaces the traditional collector-based onboarding model with a "contract" approach. Instead of shipping a collector that must be configured fo…