Expanding My Security Arsenal: From Web/API to Cloud Security
My Security Journey So Far:
Web Application Security - XSS, SQLi, CSRF, SSRF
API Security - Broken Object Level Auth, Excessive Data Exposure
Now Adding: CLOUD SECURITY - AWS, Azure, GCP penetration testing
Why Cloud Security?
As companies rush to the cloud, I'm seeing the same patterns:
"Move fast, break things" โ "Move fast, get hacked"
Shared Responsibility Model confusion
Configurations > Code vulnerabilities
Identity becoming the new perimeter
๐ฏ My Cloud Security Learning Path:
Azure Security
AWS Security
GCP Security
Multi-cloud Security (The real-world reality)
This is going to be yet another long term someyhing, Nothing good comes in fast it simply takes time, while that being said, in my early days in Tech far back as 2024 I have touched Cloud computing when I was learning all about the cloud security fundamentals and how they host users application, including their type of services like SAAS etc.
#CloudPentesting #WebExploitation #AppSec #OffensiveSecurity