To mark the start of 2026, I made a short montage of the 2025 news events that stood out to me. Wildfires in LA, AI and privacy concerns, aviation accidents, space launches, Eurovision, and Poland's rebuke to Russia at the UN.
Are cloud defenders focusing on the right issues when securing cloud environments? This is what I will be discussing during my talk at BSides Cape Town in December.
π€ BSides 2024 SPEAKER ANNOUNCEMENT π€
"Cloud Security Theater: Rising above the Noise of Misguided Strategies" - Presented by Jared Naude
"To secure cloud environments effectively, a modern operating model needs to be created to solve the real security challenges faced during cloud adoption. However, are security teams focusing on the right problems when it comes to cloud security or we are just doing Cloud Security Theater?"
Watch this space as we unveil more speakers and talks we have lined up!
These kinds of vulnerabilities extend to AssumeRoleWithWebIdentity where if a condition is not include in a trust policy, attackers could use the trust to a provider to gain unauthorized access to an AWS account. AWS has only fixed this for GitHub.
I feel vindicated after rallying against the use of CodeCommit now that AWS has decided to discontinue it. Storing code in an AWS account is a recipe for disaster.
In addition, AWS is also deprecating S3 Select, CloudSearch, Cloud9, SimpleDB, Forecast and Data Pipeline.
After giving it a lot of thought, we made the decision to discontinue new access to a small number of services, including AWS CodeCommit.
While we are no longer onboarding new customers to these services, there are no plans to change the features or experience you get today, including keeping them secure and reliable.
We also support migrations to other AWS or third-party solutions better aligned with your evolving needs. Keep the feedback coming. Weβre always listening.
Next up is the post team. 4386 postcards were sent externally of which 3125 were to Germany and 58 were to other countries. 38k postcards were used internally for the event. #37c3
37c3 infrastructure review
The infrastructure review is usually one of my favorite talks to get to see behind the scenes and the work that many teams did to make the event possible.
#37c3