<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud Security on VPN Works</title>
    <link>https://vpnw.com/tags/cloud-security/</link>
    <description>Recent content in Cloud Security on VPN Works</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 29 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://vpnw.com/tags/cloud-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cloud Metadata Case Study: Request for Instance Credentials Blocked Before Any Connection Is Made</title>
      <link>https://vpnw.com/cloud-metadata-case-study-request-for-instance-credentials-blocked-before-any-connection-is-made/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/cloud-metadata-case-study-request-for-instance-credentials-blocked-before-any-connection-is-made/</guid>
      <description>&lt;p&gt;Every major cloud runs a metadata service at the same address, 169.254.169.254, reachable from inside each virtual machine. Among other things it hands out the machine&amp;rsquo;s own credentials: on AWS, for example, the temporary keys of the role the instance runs as. An agent on a cloud machine that gets talked into fetching that address can leak keys that carry every permission the machine&amp;rsquo;s role has in the cloud account.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
