Categories
Tags
CyberSecurity Blog Posts
Secure AI agents on AWS with three IAM principles
By Evgeny Anikiev | April 15, 2026
Three Security Principles for AI Agent Access on AWS AI agents reason dynamically, making runtime decisions based on context and learned patterns. Unlike traditional applications with predictable code paths, agents …
Security response automation on AWS: getting started
By Evgeny Anikiev | January 30, 2026
Security Response Automation on AWS: Your First Steps 🛡️ When unauthorized users tamper with logging to cover their tracks, you need to respond in seconds, not hours. That's where security …
AWS blocked 150K malicious npm packages in 2025
By Evgeny Anikiev | December 27, 2025
When 150,000 malicious npm packages hit the registry in late October, AWS Security didn't panic. They moved.Over the past few months, three major campaigns targeted open-source developers: the Nx compromise …
Coordinated crypto mining hits EC2 and ECS via compromised IAM
By Evgeny Anikiev | December 27, 2025
Crypto Miners Hit AWS EC2 & ECS HardAWS GuardDuty just exposed a live, coordinated cryptomining campaign running since November 2. Here's what went down:The Attack Chain:Threat actors used compromised IAM …
HSTS across API Gateway, ALB, and CloudFront
By Evgeny Anikiev | December 14, 2025
Your distributed AWS architecture might have a security blind spot you don't even know about.That first HTTP request—the one before the browser gets redirected to HTTPS? It's a window. An …
150K malicious npm packages detected in token farming blitz
By Evgeny Anikiev | November 14, 2025
150,000 Malicious Packages Found in npm RegistryAmazon Inspector security researchers just identified what might be the largest package flooding attack ever: 150,000+ fake npm packages, all part of a coordinated …