Sign in

Scott Piper

@scottpiper.bsky.social
1.8K followers 79 following 205 posts

Cloud security historian. Developed flaws.cloud, CloudMapper, and Parliament. Founding team for fwdcloudsec.org Principal Cloud Security Researcher at Wiz.

PostsRepliesMedia
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 24/09/2026
Videos for fwd:cloudsec Europe 2026 are out! www.youtube.com/playlist?lis...
youtube.com
fwd:cloudsec Europe 2026 - YouTube
Recorded at fwd:cloudsec Europe 2026 September 7 and 8 London, UK
034
Scott Piper @scottpiper.bsky.social · 17/09/2026
AWS has a new sign up experience, which puts new accounts into a sort of a sandbox, but not exactly in the way you might think. This post explores what it does and how it works. www.wiz.io/blog/explori...
wiz.io
Exploring the new AWS Sign Up experience | Wiz Blog
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
130
Scott Piper @scottpiper.bsky.social · 31/07/2026
A lot of cloud service providers beyond AWS allow you to store data in something that looks and acts like S3, but there are differences worth investigating. Check out my latest article discussing the security risks that carry over and the assumptions that break. www.wiz.io/blog/s3-clon...
wiz.io
S3 Clones in the Neoclouds | Wiz Blog
S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.
020
Scott Piper @scottpiper.bsky.social · 27/07/2026
Happy birthday to the Cloud Security Forum Slack! It started 9 years ago and remains my favorite place for cloud security conversations with experts across the industry. fwdcloudsec.org/forum/
fwdcloudsec.org
Cloud Security Forum | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
011
Scott Piper @scottpiper.bsky.social · 23/06/2026
Yesterday the White House signed a new Executive Order moving the deadlines for Post-Quantum Cryptography closer. I presented last week on PQC to give folks an understanding of what needs to be upgraded, visibility we see, and more. www.youtube.com/watch?v=BaRu...
youtube.com
The State of Post-Quantum Cryptography
YouTube video by Wiz
020
Scott Piper @scottpiper.bsky.social · 28/05/2026
Post-Quantum Cryptography is getting attention lately, but there is barely any data out there about the progress being made... until now! www.wiz.io/blog/state-o...
wiz.io
State of Post Quantum Cryptography | Wiz Blog
Discussion of PQC relevant statistics that we see across our customers and other data sources.
020
Reposted by Scott Piper
Forrest Brazeal @forrestbrazeal.bsky.social · 22/04/2026
"Funny and distressingly realistic...propelled by awesome characters and inventive twists” — Andy Weir Silicon Valley invents the time machine in my upcoming book PARADOX INC, now available for preorder everywhere! Here's a look inside from @people.com: people.com/paradox-inc-...
people.com
Former Google Employee Announces Silicon Valley Satire, ‘Paradox Inc.’ — See the Cover! (Exclusive)
Forrest Brazael, a former Google employee, chronicles the fall and rise of a time-travel startup in his forthcoming book, ‘Paradox Inc.’
5193
Scott Piper @scottpiper.bsky.social · 24/04/2026
I'm excited for this! I see Amazon has an audiobook version for pre-order. Will you be the voice for that?
110
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 24/04/2026
The schedule for fwd:cloudsec North America is up! A few time slots are waiting for embargoes to clear. pretalx.com/fwd-cloudsec... We also still have some last minute tickets. The conference will be outside Seattle on June 1-2. fwdcloudsec.org/conference/n...
pretalx.com
https://pretalx.com/fwd-cloudsec-2026/schedule/
fwd:cloudsec 2026 Get different formats: curl https://pretalx.com/fwd-cloudsec-2026/schedule/\?format=table (default) curl https://pretalx.com/fwd-cloudsec-2026/schedule/\?format=list ...
051
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 19/03/2026
The CFP for fwd:cloudsec North America closes this Friday (March 20) at midnight Pacific time! Hotel and travel costs are taken care of for speakers (some caveats apply), plus tickets. Come speak June 1&2 near Seattle. fwdcloudsec.org/conference/n...
fwdcloudsec.org
CFP | NA 2026 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
021
Scott Piper @scottpiper.bsky.social · 13/03/2026
As a cloud security historian, it was fun to take a look at not just the what, but the why, of the changes in cloud security work over the years. www.wiz.io/blog/twenty-...
wiz.io
Twenty Years of Cloud Security Research | Wiz Blog
This post will look at the past 20 years of cloud security research, separating the two decades into eras with important milestones defined that resulted in the change of one era to the next.
052
Scott Piper @scottpiper.bsky.social · 23/02/2026
Interesting. I didn't know there was one more than region in that partition.
110
Scott Piper @scottpiper.bsky.social · 13/02/2026
Check out the the Call For Papers here: fwdcloudsec.org/conference/n...
fwdcloudsec.org
CFP | NA 2026 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
010
Scott Piper @scottpiper.bsky.social · 13/02/2026
- Practitioners! This is a conference for practitioners. Cross-tenant 0days are fun, but war stories of migrating accounts between Orgs due to M&A, migrating applications from one cloud to another, and other things practitioners do are the meat and potatoes of this conference.
110
Scott Piper @scottpiper.bsky.social · 13/02/2026
* How are you securing agents in the cloud? - Some of you have multiple AWS Organizations. How are you managing an organization of Organizations?
110
Scott Piper @scottpiper.bsky.social · 13/02/2026
- AI: Last year we received surprisingly few talks related to AI. 🤯 I know you all are using AI for all sorts of cloud security things. Let's hear about it! Examples: * How easy was it to migrate CloudFormation to terraform, or to a different cloud, with an LLM to translate?
110
Scott Piper @scottpiper.bsky.social · 13/02/2026
- Cloud concepts brought back to datacenters: For years people have turned their old existing datacenters into "clouds", but now you have people who have only ever used the cloud moving to datacenters. What did they bring with them?
110
Scott Piper @scottpiper.bsky.social · 13/02/2026
- Neoclouds: CoreWeave, Vercel, and other code execution as-a-service. How are you securing (or abusing) those? - Multi-partitions: How are you leveraging both AWS standard and European Sovereign Cloud? Any unexpected gotchas in ESC or other partitions?
210
Scott Piper @scottpiper.bsky.social · 13/02/2026
It pains me when I hear people say "I thought about submitting a talk to the fwd:cloudsec, but didn't because..." and the reasons are often things I actually want to see presentations on! Some talk ideas I personally want to watch (the other reviewers and I will fight ⚔️):
131
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 09/02/2026
Tickets for fwd:cloudsec North America go on sale today, in about 4 hours, at 10am PST. fwdcloudsec.org/conference/n...
fwdcloudsec.org
fwd:cloudsec North America 2026 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
023
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 02/02/2026
Tickets go on sale next week on Monday, Feb 9, at 10:00 a.m. PST for our North American conference happening near Seattle on June 1 and 2. An additional small batch will go on sale that evening at 11:00 p.m. PST. Tickets will be available for purchase here: www.eventbrite.com/e/fwdcloudse...
eventbrite.com
fwd:cloudsec North America 2026
fwd:cloudsec is the industry's leading independent, community-driven cloud security conference. All times listed are in US/Pacific time.
111
Reposted by Scott Piper
Zack Glick @z1g1.net · 20/01/2026
@fwdcloudsec.org is an awesome conference. Looking forward to seeing lots of cool submissions into the CFP!
011
Reposted by Scott Piper
Nick Frichette @frichetten.com · 21/01/2026
Did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset. It's the EICAR test string of the AI age. Details: hackingthe.cloud/ai-llm/explo...
hackingthe.cloud
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud
How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.
0101
Reposted by Scott Piper
fwd:cloudsec @fwdcloudsec.org · 20/01/2026
We've locked in dates and venues for the North American (NA) and European (EU) fwd:cloudsec conferences this year! fwd:cloudsec NA will be in the Seattle, Washington area at the Meydenbauer Center in Bellevue on June 1 and 2. 🧵
1137
Scott Piper @scottpiper.bsky.social · 16/01/2026
What are we calling normal AWS now? Normal, standard, classic, commercial, global, american? How do you say out loud the acronym for AWS European Sovereign Cloud? I'm calling it "oosk", because the region is eusc-de-east-1, which sounds like a riff on the techno onomatopoeia "boots and cats".
130
Scott Piper @scottpiper.bsky.social · 16/01/2026
The most surprising thing about AWS ESC is there aren't any cookie acceptance popup windows in the console. Is this really European?
120
Reposted by Scott Piper
Nick Frichette @frichetten.com · 15/01/2026
Very cool research on a CodeBuild misconfiguration which could have had significant consequences. I’m a bit disappointed that there wasn’t more done to secure the supply chain after the Q Developer incident. www.wiz.io/blog/wiz-res...
wiz.io
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog
Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.
032
Reposted by Scott Piper
Luc van Donkersgoed @lucvandonkersgoed.com · 15/01/2026
The AWS European Sovereign Cloud (ESC) has launched! aws-news.com/article/2026...
aws-news.com
Opening the AWS European Sovereign Cloud
AWS European Sovereign Cloud is now generally available, offering EU-based organizations independent cloud infrastructure with enhanced sovereignty controls, E...
141
Reposted by Scott Piper
Corey Quinn @quinnypig.com · 15/01/2026
This seems bad. www.wiz.io/blog/wiz-res...
wiz.io
CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog
Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.
0206
Reposted by Scott Piper
zoph @zoph.me · 19/12/2025
December is generally a good time for gifts, and I have a special one for you. We are glad to announce fwd:cloudsec Europe 2026: September 7th and 8th - London, UK 🇬🇧 More info to come early 2026. Stay tuned, folks.
061
Scott Piper @scottpiper.bsky.social · 16/12/2025
This is the best write-up on threat actor tradecraft I've seen from AWS. aws.amazon.com/blogs/securi...
aws.amazon.com
Cryptomining campaign targeting Amazon EC2 and Amazon ECS | Amazon Web Services
Amazon GuardDuty and our automated security monitoring systems identified an ongoing cryptocurrency (crypto) mining campaign beginning on November 2, 2025. The operation uses compromised AWS Identity ...
021
Scott Piper @scottpiper.bsky.social · 08/12/2025
My top picks from re:Invent security announcements: www.wiz.io/blog/top-aws...
wiz.io
Top AWS re:Invent Announcements for Security Teams in 2025 | Wiz Blog
The re:Invent announcements that are most impactful to security teams.
061
Scott Piper @scottpiper.bsky.social · 04/12/2025
This is excellent. Also available in video. allan.reyes.sh/posts/keepin... h/t tldrsec
allan.reyes.sh
Keeping Secrets Out of Logs
There's no silver bullet, but if we put some "lead" bullets in the right places, we have a good shot at keeping sensitive data out of logs.
050
Reposted by Scott Piper
Wiz io @wiz.io · 27/11/2025
It’s time to bust some malware! 🦠 Challenge #6 “Malware Busters” is LIVE. Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside. Think you can crack it? cloudsecuritychampionship.com/challenge/6
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
021
Reposted by Scott Piper
Wiz io @wiz.io · 24/11/2025
🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast. Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation. Details: www.wiz.io/blog/shai-hu...
wiz.io
Shai-Hulud 2.0: Ongoing Supply Chain Attack | Wiz Blog
Detect and mitigate malicious npm packages linked to the recent Shai-Hulud-style campaign. Over 25,000 affected repositories across ~350 unique users.
052
Reposted by Scott Piper
Mike Julian @mikejulian.com · 18/11/2025
The day has come where we get to announce what we've been working on for the past year 😍 www.duckbillhq.com/blog/skyway-...
duckbillhq.com
Skyway: Cloud cost management for the 9-figure club
Introducing Skyway: contract management for enterprise cloud spend. Built by the team overseeing tens-of-billions in enterprise cloud spend.
5163
Scott Piper @scottpiper.bsky.social · 11/11/2025
My favorite security story I've read this year 😂, a story of surprising turns by Alex Smolen: engseclabs.com/blog/raccoon...
engseclabs.com
Backyard APT: A Raccoon Story
Raccoons are both advanced and persistent threats. After one attacked my chihuahua Jolene, I declared war on my backyard invaders. Through ultrasonic deterrents, motion-activated sprinklers, and wacky...
011
Scott Piper @scottpiper.bsky.social · 27/10/2025
Yuval Avrahami was ranked as the top Azure researcher by Microsoft this quarter! He has made a Kubernetes focused CTF for the Wiz Cloud Security Championship, check it out! cloudsecuritychampionship.com Also if you can find cloud zero days, check out www.zeroday.cloud with a $4.5M prize pool!
030
Reposted by Scott Piper
Forrest Brazeal @forrestbrazeal.bsky.social · 23/10/2025
I feel like the biggest takeaway from the latest AWS outage is that there’s simply no architecting around them at this point. Even if you are 100% redundant/multi-whatever, your vendors and customers are certainly not. Order volume is dropping no matter what you do. We’re all in this together.
4272
Scott Piper @scottpiper.bsky.social · 13/10/2025
I used to drink a gallon of milk a day, so this is just being more efficient.
000
Scott Piper @scottpiper.bsky.social · 13/10/2025
Jeep pushed a bad update on Friday that has been bricking 2024 Wrangle 4xe's. x.com/StephenGutow...
x.com
Stephen Gutowski on X: "Jeep just pushed a software update that bricked all the 2024 Wrangler 4xe models, including my Willys. The future is going great." / X
Jeep just pushed a software update that bricked all the 2024 Wrangler 4xe models, including my Willys. The future is going great.
000
Scott Piper @scottpiper.bsky.social · 06/10/2025
A company's website, API, and email were unavailable because "attackers socially engineered AWS into freezing its domain". www.theregister.com/2025/10/02/s...
theregister.com
Kodex outage blamed on AWS social engineering attack
: Software maker Kodex said its domain registrar fell for a fraudulent legal order
051
Reposted by Scott Piper
Wiz io @wiz.io · 30/09/2025
Introducing ZERODAY.CLOUD🕵️‍♀️ Be the first to participate in the first-of-its-kind cloud hacking competition. 🤝 WIN HUGE PRIZES from our up to 4.5 million dollar prize pool. 💰🏆 Join us to help make the cloud a safer place. Register your exploit now >> zeroday.cloud
011
Scott Piper @scottpiper.bsky.social · 30/09/2025
I really like the announcements that have been coming out of Cloudflare. In this latest one, SSO for everyone (not just enterprise). blog.cloudflare.com/enterprise-g... Another recent and interesting one is their data platform: blog.cloudflare.com/cloudflare-d...
blog.cloudflare.com
Every Cloudflare feature, available to everyone
Cloudflare is making every feature available to any customer.
020
Reposted by Scott Piper
Richard Fan @richardfan.xyz · 30/09/2025
After facing countless of limitation on #AWS #NitroEnclaves, the same feature is now available on normal EC2 instance. The coming month must be a busy month for me to try it out #ConfidentialComputing #AWSCloud aws.amazon.com/about-aws/wh...
aws.amazon.com
AWS announces EC2 instance attestation - AWS
Discover more about what's new at AWS with AWS announces EC2 instance attestation
051
Scott Piper @scottpiper.bsky.social · 29/09/2025
S3 SOAP API is being deprecated in a month (Oct 31). docs.aws.amazon.com/AmazonS3/lat... h/t @quinnypig.com for pointing it out in @lastweekinaws.com
docs.aws.amazon.com
Appendix: SOAP API - Amazon Simple Storage Service
Describes the SOAP API with respect to service, bucket, and object operations that you can perform on the Amazon S3 web service.
140
Scott Piper @scottpiper.bsky.social · 26/09/2025
The first step toward an organization of organizations. aws.amazon.com/about-aws/wh...
aws.amazon.com
Billing View now supports cost management data from multiple organizations - AWS
Discover more about what's new at AWS with Billing View now supports cost management data from multiple organizations
000
Scott Piper @scottpiper.bsky.social · 24/09/2025
These include: - SSO - SSO-admin, which oddly uses arn:aws:trebuchet::: - controlcatalog - trustedadivsor - route53 healthcheck - Multi-party Approval qualified policies, which just ignores the arn format entirely with a 64 digit "partition". github.com/boto/botocor...
github.com
010
Scott Piper @scottpiper.bsky.social · 24/09/2025
Random thing I noticed which I don't think has value but I'm recording it anyway: S3 is known to have a global namespace which can be seen with the ":::" in the arn. Ex. arn:aws:s3:::amzn-s3-demo-bucket. But other global namespaces exist. 1/2
140
Scott Piper @scottpiper.bsky.social · 24/09/2025
Gal Nagli has opened my eyes to a speed and scale of web hacking that would be terrifying if he wasn't using those skills to help companies. He has put together a CTF challenge to showcase some of his most effective techniques. Check it out! www.cloudsecuritychampionship.com/challenge/4
cloudsecuritychampionship.com
The Ultimate Cloud Security Championship | 12 Months × 12 Challenges
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
140