Please turn JavaScript on
header-image

Sonrai | Enterprise Cloud Security Platform

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.08 / day

Message History

As January 2026 comes to a close, Sonrai’s latest review of newly released AWS permissions highlights a sharp expansion of privilege concentrated in networking, traffic control, and collaboration services. This month’s updates focus heavily on AWS Network Firewall, Route 53 Global Resolver, EC2 networking controls, and cross-account data collaboration, introducing new ways to...


Read full story
Why I Stopped JIT’ing Users and Started JIT’ing Permissions

By Cole HorsmanField CTO, Sonrai Security

I first tried to “shift left” cloud identity in early 2020.

We were building a greenfield AWS environment with a strong cloud team and leadership support to do things properly. The idea was familiar: pu...


Read full story

As December 2025 comes to a close, Sonrai’s latest review of newly released AWS permissions highlights a continued expansion of cloud privilege. This month’s updates span identity, observability, AI, and managed service infrastructure, with changes across CloudWatch, CloudFront, Bedrock, EKS, SageMaker, and emerging agent-based platforms.

Together, these permissions...


Read full story

The recent discovery of a cryptomining campaign targeting Amazon compute resources highlights a critical gap in traditional cloud defense. Attackers are bypassing perimeter defenses by leveraging compromised credentials to ...


Read full story

Privilege escalation in AWS is evolving. Classic IAM issues still matter, but attackers now exploit service-based execution paths, orchestration layers, and new AI-driven services like Bedrock and Bedrock AgentCore. Sonrai Security partnered with Software Secured to exploit a number of ...


Read full story