Sign in

Scott Piper

@scottpiper.bsky.social
1.8K followers 79 following 205 posts

Cloud security historian. Developed flaws.cloud, CloudMapper, and Parliament. Founding team for fwdcloudsec.org Principal Cloud Security Researcher at Wiz.

PostsRepliesMedia
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 24/09/2026
Videos for fwd:cloudsec Europe 2026 are out! www.youtube.com/playlist?lis...
youtube.com
fwd:cloudsec Europe 2026 - YouTube
Recorded at fwd:cloudsec Europe 2026 September 7 and 8 London, UK
034
Scott Piper @scottpiper.bsky.social · 17/09/2026
AWS has a new sign up experience, which puts new accounts into a sort of a sandbox, but not exactly in the way you might think. This post explores what it does and how it works. www.wiz.io/blog/explori...
wiz.io
Exploring the new AWS Sign Up experience | Wiz Blog
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
130
Scott Piper @scottpiper.bsky.social · 31/07/2026
A lot of cloud service providers beyond AWS allow you to store data in something that looks and acts like S3, but there are differences worth investigating. Check out my latest article discussing the security risks that carry over and the assumptions that break. www.wiz.io/blog/s3-clon...
wiz.io
S3 Clones in the Neoclouds | Wiz Blog
S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.
020
Scott Piper @scottpiper.bsky.social · 27/07/2026
Happy birthday to the Cloud Security Forum Slack! It started 9 years ago and remains my favorite place for cloud security conversations with experts across the industry. fwdcloudsec.org/forum/
fwdcloudsec.org
Cloud Security Forum | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
011
Scott Piper @scottpiper.bsky.social · 23/06/2026
Yesterday the White House signed a new Executive Order moving the deadlines for Post-Quantum Cryptography closer. I presented last week on PQC to give folks an understanding of what needs to be upgraded, visibility we see, and more. www.youtube.com/watch?v=BaRu...
youtube.com
The State of Post-Quantum Cryptography
YouTube video by Wiz
020
Scott Piper @scottpiper.bsky.social · 28/05/2026
Post-Quantum Cryptography is getting attention lately, but there is barely any data out there about the progress being made... until now! www.wiz.io/blog/state-o...
wiz.io
State of Post Quantum Cryptography | Wiz Blog
Discussion of PQC relevant statistics that we see across our customers and other data sources.
020
Reposted by Scott Piper
Forrest Brazeal @forrestbrazeal.bsky.social · 22/04/2026
"Funny and distressingly realistic...propelled by awesome characters and inventive twists” — Andy Weir Silicon Valley invents the time machine in my upcoming book PARADOX INC, now available for preorder everywhere! Here's a look inside from @people.com: people.com/paradox-inc-...
people.com
Former Google Employee Announces Silicon Valley Satire, ‘Paradox Inc.’ — See the Cover! (Exclusive)
Forrest Brazael, a former Google employee, chronicles the fall and rise of a time-travel startup in his forthcoming book, ‘Paradox Inc.’
5193
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 24/04/2026
The schedule for fwd:cloudsec North America is up! A few time slots are waiting for embargoes to clear. pretalx.com/fwd-cloudsec... We also still have some last minute tickets. The conference will be outside Seattle on June 1-2. fwdcloudsec.org/conference/n...
pretalx.com
https://pretalx.com/fwd-cloudsec-2026/schedule/
fwd:cloudsec 2026 Get different formats: curl https://pretalx.com/fwd-cloudsec-2026/schedule/\?format=table (default) curl https://pretalx.com/fwd-cloudsec-2026/schedule/\?format=list ...
051
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 19/03/2026
The CFP for fwd:cloudsec North America closes this Friday (March 20) at midnight Pacific time! Hotel and travel costs are taken care of for speakers (some caveats apply), plus tickets. Come speak June 1&2 near Seattle. fwdcloudsec.org/conference/n...
fwdcloudsec.org
CFP | NA 2026 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
021
Scott Piper @scottpiper.bsky.social · 13/03/2026
As a cloud security historian, it was fun to take a look at not just the what, but the why, of the changes in cloud security work over the years. www.wiz.io/blog/twenty-...
wiz.io
Twenty Years of Cloud Security Research | Wiz Blog
This post will look at the past 20 years of cloud security research, separating the two decades into eras with important milestones defined that resulted in the change of one era to the next.
052
Scott Piper @scottpiper.bsky.social · 13/02/2026
It pains me when I hear people say "I thought about submitting a talk to the fwd:cloudsec, but didn't because..." and the reasons are often things I actually want to see presentations on! Some talk ideas I personally want to watch (the other reviewers and I will fight ⚔️):
131
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 09/02/2026
Tickets for fwd:cloudsec North America go on sale today, in about 4 hours, at 10am PST. fwdcloudsec.org/conference/n...
fwdcloudsec.org
fwd:cloudsec North America 2026 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
023
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 02/02/2026
Tickets go on sale next week on Monday, Feb 9, at 10:00 a.m. PST for our North American conference happening near Seattle on June 1 and 2. An additional small batch will go on sale that evening at 11:00 p.m. PST. Tickets will be available for purchase here: www.eventbrite.com/e/fwdcloudse...
eventbrite.com
fwd:cloudsec North America 2026
fwd:cloudsec is the industry's leading independent, community-driven cloud security conference. All times listed are in US/Pacific time.
111
Reposted by Scott Piper
Zack Glick @z1g1.net · 20/01/2026
@fwdcloudsec.org is an awesome conference. Looking forward to seeing lots of cool submissions into the CFP!
011
Reposted by Scott Piper
Nick Frichette @frichetten.com · 21/01/2026
Did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset. It's the EICAR test string of the AI age. Details: hackingthe.cloud/ai-llm/explo...
hackingthe.cloud
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud
How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.
0101
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 20/01/2026
We've locked in dates and venues for the North American (NA) and European (EU) fwd:cloudsec conferences this year! fwd:cloudsec NA will be in the Seattle, Washington area at the Meydenbauer Center in Bellevue on June 1 and 2. 🧵
1137
Scott Piper @scottpiper.bsky.social · 16/01/2026
What are we calling normal AWS now? Normal, standard, classic, commercial, global, american? How do you say out loud the acronym for AWS European Sovereign Cloud? I'm calling it "oosk", because the region is eusc-de-east-1, which sounds like a riff on the techno onomatopoeia "boots and cats".
130
Scott Piper @scottpiper.bsky.social · 16/01/2026
The most surprising thing about AWS ESC is there aren't any cookie acceptance popup windows in the console. Is this really European?
120
Reposted by Scott Piper
Nick Frichette @frichetten.com · 15/01/2026
Very cool research on a CodeBuild misconfiguration which could have had significant consequences. I’m a bit disappointed that there wasn’t more done to secure the supply chain after the Q Developer incident. www.wiz.io/blog/wiz-res...
wiz.io
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog
Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.
032
Reposted by Scott Piper
Luc van Donkersgoed @lucvandonkersgoed.com · 15/01/2026
The AWS European Sovereign Cloud (ESC) has launched! aws-news.com/article/2026...
aws-news.com
Opening the AWS European Sovereign Cloud
AWS European Sovereign Cloud is now generally available, offering EU-based organizations independent cloud infrastructure with enhanced sovereignty controls, E...
141
Reposted by Scott Piper
Corey Quinn @quinnypig.com · 15/01/2026
This seems bad. www.wiz.io/blog/wiz-res...
wiz.io
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog
Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.
0206
Reposted by Scott Piper
zoph @zoph.me · 19/12/2025
December is generally a good time for gifts, and I have a special one for you. We are glad to announce fwd:cloudsec Europe 2026: September 7th and 8th - London, UK 🇬🇧 More info to come early 2026. Stay tuned, folks.
061
Scott Piper @scottpiper.bsky.social · 16/12/2025
This is the best write-up on threat actor tradecraft I've seen from AWS. aws.amazon.com/blogs/securi...
aws.amazon.com
Cryptomining campaign targeting Amazon EC2 and Amazon ECS | Amazon Web Services
Amazon GuardDuty and our automated security monitoring systems identified an ongoing cryptocurrency (crypto) mining campaign beginning on November 2, 2025. The operation uses compromised AWS Identity ...
021
Scott Piper @scottpiper.bsky.social · 08/12/2025
My top picks from re:Invent security announcements: www.wiz.io/blog/top-aws...
wiz.io
Top AWS re:Invent Announcements for Security Teams in 2025 | Wiz Blog
The re:Invent announcements that are most impactful to security teams.
061
Scott Piper @scottpiper.bsky.social · 04/12/2025
This is excellent. Also available in video. allan.reyes.sh/posts/keepin... h/t tldrsec
allan.reyes.sh
Keeping Secrets Out of Logs
There's no silver bullet, but if we put some "lead" bullets in the right places, we have a good shot at keeping sensitive data out of logs.
050
Reposted by Scott Piper
Wiz io @wiz.io · 27/11/2025
It’s time to bust some malware! 🦠 Challenge #6 “Malware Busters” is LIVE. Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside. Think you can crack it? cloudsecuritychampionship.com/challenge/6
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
021
Reposted by Scott Piper
Wiz io @wiz.io · 24/11/2025
🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast. Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation. Details: www.wiz.io/blog/shai-hu...
wiz.io
Shai-Hulud 2.0: Ongoing Supply Chain Attack | Wiz Blog
Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users.
052
Reposted by Scott Piper
Mike Julian @mikejulian.com · 18/11/2025
The day has come where we get to announce what we've been working on for the past year 😍 www.duckbillhq.com/blog/skyway-...
duckbillhq.com
Skyway: Cloud cost management for the 9-figure club
Introducing Skyway: contract management for enterprise cloud spend. Built by the team overseeing tens-of-billions in enterprise cloud spend.
4153
Scott Piper @scottpiper.bsky.social · 11/11/2025
My favorite security story I've read this year 😂, a story of surprising turns by Alex Smolen: engseclabs.com/blog/raccoon...
engseclabs.com
Backyard APT: A Raccoon Story
Raccoons are both advanced and persistent threats. After one attacked my chihuahua Jolene, I declared war on my backyard invaders. Through ultrasonic deterrents, motion-activated sprinklers, and wacky...
011
Scott Piper @scottpiper.bsky.social · 27/10/2025
Yuval Avrahami was ranked as the top Azure researcher by Microsoft this quarter! He has made a Kubernetes focused CTF for the Wiz Cloud Security Championship, check it out! cloudsecuritychampionship.com Also if you can find cloud zero days, check out www.zeroday.cloud with a $4.5M prize pool!
030
Reposted by Scott Piper
Forrest Brazeal @forrestbrazeal.bsky.social · 23/10/2025
I feel like the biggest takeaway from the latest AWS outage is that there’s simply no architecting around them at this point. Even if you are 100% redundant/multi-whatever, your vendors and customers are certainly not. Order volume is dropping no matter what you do. We’re all in this together.
4272
Scott Piper @scottpiper.bsky.social · 13/10/2025
Jeep pushed a bad update on Friday that has been bricking 2024 Wrangle 4xe's. x.com/StephenGutow...
x.com
Stephen Gutowski on X: "Jeep just pushed a software update that bricked all the 2024 Wrangler 4xe models, including my Willys. The future is going great." / X
Jeep just pushed a software update that bricked all the 2024 Wrangler 4xe models, including my Willys. The future is going great.
000
Scott Piper @scottpiper.bsky.social · 06/10/2025
A company's website, API, and email were unavailable because "attackers socially engineered AWS into freezing its domain". www.theregister.com/2025/10/02/s...
theregister.com
Kodex outage blamed on AWS social engineering attack
: Software maker Kodex said its domain registrar fell for a fraudulent legal order
051
Reposted by Scott Piper
Wiz io @wiz.io · 30/09/2025
Introducing ZERODAY.CLOUD🕵️‍♀️ Be the first to participate in the first-of-its-kind cloud hacking competition. 🤝 WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. 💰🏆 Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud
011
Scott Piper @scottpiper.bsky.social · 30/09/2025
I really like the announcements that have been coming out of Cloudflare. In this latest one, SSO for everyone (not just enterprise). blog.cloudflare.com/enterprise-g... Another recent and interesting one is their data platform: blog.cloudflare.com/cloudflare-d...
blog.cloudflare.com
Every Cloudflare feature, available to everyone
Cloudflare is making every feature available to any customer.
020
Reposted by Scott Piper
Richard Fan @richardfan.xyz · 30/09/2025
After facing countless of limitation on #AWS #NitroEnclaves, the same feature is now available on normal EC2 instance. The coming month must be a busy month for me to try it out #ConfidentialComputing #AWSCloud aws.amazon.com/about-aws/wh...
aws.amazon.com
AWS announces EC2 instance attestation - AWS
Discover more about what's new at AWS with AWS announces EC2 instance attestation
051
Scott Piper @scottpiper.bsky.social · 29/09/2025
S3 SOAP API is being deprecated in a month (Oct 31). docs.aws.amazon.com/AmazonS3/lat... h/t @quinnypig.com for pointing it out in @lastweekinaws.com
docs.aws.amazon.com
Appendix: SOAP API - Amazon Simple Storage Service
Describes the SOAP API with respect to service, bucket, and object operations that you can perform on the Amazon S3 web service.
140
Scott Piper @scottpiper.bsky.social · 26/09/2025
The first step toward an organization of organizations. aws.amazon.com/about-aws/wh...
aws.amazon.com
Billing View now supports cost management data from multiple organizations - AWS
Discover more about what's new at AWS with Billing View now supports cost management data from multiple organizations
000
Scott Piper @scottpiper.bsky.social · 24/09/2025
Random thing I noticed which I don't think has value but I'm recording it anyway: S3 is known to have a global namespace which can be seen with the ":::" in the arn. Ex. arn:aws:s3:::amzn-s3-demo-bucket. But other global namespaces exist. 1/2
140
Scott Piper @scottpiper.bsky.social · 24/09/2025
Gal Nagli has opened my eyes to a speed and scale of web hacking that would be terrifying if he wasn't using those skills to help companies. He has put together a CTF challenge to showcase some of his most effective techniques. Check it out! www.cloudsecuritychampionship.com/challenge/4
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
140
Scott Piper @scottpiper.bsky.social · 24/09/2025
A write-up that believes this story is propaganda and might have just been for spam. cybersect.substack.com/p/that-secre...
cybersect.substack.com
That Secret Service SIM farm story is bogus
It's just normal crime
010
Scott Piper @scottpiper.bsky.social · 23/09/2025
The secret service found a setup for disrupting cell services in the NYC area. www.secretservice.gov/newsroom/rel...
secretservice.gov
U.S. Secret Service dismantles imminent telecommunications threat in New York tristate area | United States Secret Service
000
Scott Piper @scottpiper.bsky.social · 23/09/2025
GitHub's plan to better secure the npm supply chain: github.blog/security/sup...
github.blog
Our plan for a more secure npm supply chain
GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
040
Reposted by Scott Piper
zoph @zoph.me · 15/09/2025
Check out the full schedule here: fwdcloudsec.org/conference/... Not in Berlin? No worries, you can join us live on YouTube: www.youtube.com/live/-a9Ts7... It's going to be a packed day of sharp insights and real-world lessons for cloud security l33ts.
youtube.com
fwd:cloudsec Europe 2025 - Day 1
Full schedule: https://fwdcloudsec.org/conference/north-america/schedule.htmlJoin the conversation on Slack: https://fwdcloudsec.org/forum/
022
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 15/09/2025
fwd:cloudsec Europe is now live from Berlin! Watch the livestream here: youtube.com/live/-a9Ts7A...
youtube.com
fwd:cloudsec Europe 2025 - Day 1
YouTube video by fwd:cloudsec
053
Scott Piper @scottpiper.bsky.social · 03/09/2025
An interesting evolution in malware that occurred in roughly the past month is malware calling AI from the payload. We've seen malware and other artifacts (ex. phishing emails) as the OUTPUT of AI, but now malware is bringing the INPUT to AI. 1/2
111
Reposted by Scott Piper
Mostafa Moradian @mosi.bsky.social · 26/08/2025
How do you know you're compromised? Read my newest article to see how we used canary tokens to detect an attack on our infrastructure. grafana.com/blog/2025/08...
grafana.com
Canary tokens: Learn all about the unsung heroes of security at Grafana Labs | Grafana Labs
Learn why the use of canary tokens let us spot a recent intrusion and swarm quickly in response, and find out why you should be using canary tokens to prevent serious security incidents in the future.
065
Scott Piper @scottpiper.bsky.social · 25/08/2025
Netskope filing for their IPO. From their S-1, $707M ARR with $354M annual net loss. www.sec.gov/Archives/edg...
sec.gov
S-1
010
Reposted by Scott Piper
Nick Frichette @frichetten.com · 19/08/2025
Old and busted: Cloud attackers making noisy List/Describe calls. New hotness: Laundering enumeration calls through an AWS service silently. Or at least, that used to work, until @datadoghq.com partnered with AWS to close this gap. Read more here: securitylabs.datadoghq.com/articles/enu...
securitylabs.datadoghq.com
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer | Datadog Security Labs
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
0104
Reposted by Scott Piper
Corey Quinn @quinnypig.com · 13/08/2025
Working on a blog post: what AWS things aren’t true anymore, but used to be? Example: I still get surprised that I don’t have to shut down an ec2 instance to change its security group.
21625