Security
Filed under
4 posts
Agent Auth on AWS: OIDC In, Access Keys Out
Agents on AWS should never hold long-lived keys. How OIDC federation, IRSA, Roles Anywhere, and AgentCore Identity turn signed proof into temporary credentials.
Checking Cloud with Cloud: M365 Security Posture Scanning 101
Your Microsoft 365 tenant is cloud infrastructure and it drifts. A 101 on posture scanning with CIS, EIDSCA, and CISA ScuBA, and why the scanner is SaaS too.
AWS Multi-party Approval for Organizations
Multi-party approval in AWS Organizations gates high-risk operations behind a quorum of human approvers. Here is how it works and the security it buys.
Why Your SSH Is Yelling About Quantum Computers (And How to Fix It)
OpenSSH now warns when key exchange is not post-quantum. What store now, decrypt later actually threatens, and the Kex configuration that clears the warning.