Learning from AWS (Customer) Security Breaches with Rami McCarthy
▬▬▬▬▬▬ SHOW SPONSOR ✨ ▬▬▬▬▬▬ As a special offer for the OWASP DevSlop audience, sign up for a free 2-week Datadog trial and receive a Datadog t-shirt! https://www.datadoghq.com/owasp-devslop ▬▬▬▬▬▬ SHOW SPONSOR ✨ ▬▬▬▬▬▬ This show will discuss the public catalog of AWS Customer Security Incidents (https://github.com/ramimac/aws-custom..., covering over twenty different public breaches. We’ll walk through the technical details of these attacks, establish the common root causes, look at lessons learned, and establish how you can proactively secure your environment against these real-world risks. Rami McCarthy Rami McCarthy is a Staff Security Engineer and reformed Security Consultant. He currently works at Cedar, scaling up security for a health-tech unicorn. He previously worked with NCC Group to assess & secure multiple Fortune 500 and most of the Big Five tech companies. Rami is the creator of sadcloud - a tool for terraform-ing purposefully insecure AWS infrastructure and is a contributor to ScoutSuite - an open-source multi-cloud auditing tool. He holds a B.S. in Computer Science and cybersecurity from Northeastern and an M.S. in Information Security Leadership from Brandeis. ▬▬▬▬▬▬ LINKS ✨ ▬▬▬▬▬▬ SLIDES: https://speakerdeck.com/ramimac/learn... BLOG POSTS http://ramimac.me/cloudsec/security/a... Tool recommendation: https://github.com/iann0036/iamlive https://github.com/salesforce/cloudsp...

Building Modern Access-Control for Cloud Applications

Let’s Write Security Unit Tests! with Eric Johnson

Attacking AI - Jason Haddix - NDC Security 2026

Attacking JSON Web Tokens with Louis Nyffenegger

AWS Explained: The Most Important AWS Services To Know

Don't Get Got! How to Avoid a Privacy Disaster with Samantha Floreani

Zero to CTI: A Novice’s Journey into Threat Intelligence

Software Security Education with the OWASP Secure Coding Dojo

Top 10 CI/CD Security Risks

Web Scraping Using Python For Beginners and File Handling in Python | Python Web Scraping

What is SonarQube | Introduction SonarQube | SonarQube Tutorial | SonarQube Basics | Intellipaat

Github Actions Security Best Practices with Reethi Kotti

Cybersecurity Architecture: Who Are You? Identity and Access Management

The most rational take on AI you’ll hear this year

Essential AWS Security Best Practices: Building Workloads the Well-Architected Way | AWS Events

System Design Explained: APIs, Databases, Caching, CDNs, Load Balancing & Production Infra

Diving Deeper into Subdomain Takeovers & Mitigations with Shubham Shah

Account Security beyond 2FA with Neil Matatall

Project “Make ISO Happen 2022” - The Octopus Deploy Adventure Towards 27001 Certification

