Posts on cloud-security
4 posts on cloud-security. Notes from public sources and my own test lab.
Görünmez Duvarları Aşmak: PDF Generator'dan Cloud Metadata'ya Uzanan O Tehlikeli Yol
Bir PDF oluşturma servisinin nasıl bir iç ağ casusuna dönüştüğünü ve bulut ortamındaki en değerli anahtarların nasıl tehlikeye girdiğini teknik bir kriz anıyla inceliyoruz.
June 18, 2026·3 dk readcloud-securitydefensered-teaming
The Shadow Creeping Behind the Walls: Anatomy of SSRF and Those 'Innocent' Looking Parameters
A deep dive into Server-Side Request Forgery (SSRF), exploring how 'innocent' URL parameters can lead to full cloud environment compromise, shared from the perspective of a Red Team Lead.
April 22, 2026·3 dk readcloud-securitydefensered-teaming
Leaving the Key in the Lock: Why We’re Still Failing at Identity Management
Million-dollar security is useless if you leave your AWS keys in a script. Let's talk about why IAM is still our weakest link and how to fix it.
February 5, 2026·4 dk readcloud-securityiamidentity-management
The "Root" Illusion in Container Land: How Not to Score an Own Goal
Just because it's in a container doesn't mean it's secure. Let's talk about the common mistakes that turn your isolated box into an open door.
February 5, 2026·4 dk readcloud-securitydevsecopsdocker