veganism.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Veganism Social is a welcoming space on the internet for vegans to connect and engage with the broader decentralized social media community.

Administered by:

Server stats:

291
active users

#ecs

6 posts6 participants0 posts today

🚨 Insider Threats: The Risk Within 🚨
Not all cyber threats come from the outside. Sometimes, the danger is already inside your organization.

🔍 Discover:
✅ Types of insider threats
✅ Real-world cases
✅ Risks & impact
✅ Proven prevention strategies

🛡 Protect your business before it’s too late!

Read more 👉 ecsinfotech.com/what-are-insid

🌘 ECScape:解析 Amazon ECS 的 IAM 權限邊界
➤ 揭露 Amazon ECS 內部機制,解析容器間 IAM 憑證竊取技術
sweet.security/blog/ecscape-un
本文深入探討了 Amazon ECS (Elastic Container Service) 的一個潛在安全風險,該風險源於跨任務的 IAM 憑證暴露。研究人員發現,一個較低權限的容器可以利用 ECS 的內部協定,從同一 EC2 主機上其他具有較高權限的任務竊取 AWS 憑證。這種被稱為「ECScape」的技術,實際上是利用了 ECS agent 與控制平面之間的通信機制,從而繞過了 AWS 文件中關於任務執行角色無法被容器存取的聲明。文章詳細解釋了這種攻擊如何運作、其潛在影響,並提出了相應的緩解措施,包括任務隔離、限制 IMDS 存取以及實施最小權限原則。
+ 這篇研究非常及時!在我們大量
#AWS #ECS #IAM #資安研究 #容器安全 #漏洞

www.sweet.securityECScape: Understanding IAM Privilege Boundaries in Amazon ECSECScape: Understanding IAM Privilege Boundaries in Amazon ECS

"Cybersecurity researchers have demonstrated an "end-to-end privilege escalation chain" in Amazon Elastic Container Service (ECS) that could be exploited by an attacker to conduct lateral movement, access sensitive data, and seize control of the cloud environment.

The attack technique has been codenamed ECScape by Sweet Security researcher Naor Haziz, who presented the findings today at the Black Hat USA security conference that's being held in Las Vegas.

"We identified a way to abuse an undocumented ECS internal protocol to grab AWS credentials belonging to other ECS tasks on the same EC2 instance," Haziz said in a report shared with The Hacker News. "A malicious container with a low‑privileged IAM [Identity and Access Management] role can obtain the permissions of a higher‑privileged container running on the same host."

Amazon ECS is a fully-managed container orchestration service that allows users to deploy, manage, and scale containerized applications, while integrating with Amazon Web Services (AWS) to run container workloads in the cloud."

thehackernews.com/2025/08/rese

The Hacker NewsResearchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential TheftECS agent on EC2 exposes IAM credentials to containers, risking cross-task access without proper isolation.
Replied in thread

@th0ma5 Supporting n-polygonal faces, polyline graphs (i.e. meshes with only edges, but without faces) and improving sparse nD attrib storage are exactly the reasons why I haven't publicly released my "new" mesh impl yet and why I started refactoring it in/since 2019, after (and because) I created thi.ng/ecs, which I was going to use as backend for it. This ECS implementation uses thi.ng/sparse-set to store sparse attributes (components) in a dense manner and also supports memory mapped components to enable zero-copy updates and direct passing of buffers to WASM/WebGL/WebGPU. The thi.ng/soa, thi.ng/vector-pools and thi.ng/simd are all packages which exist for similar purposes (originally/indirectly also created for this mesh project). At this point, I'm having several open redesigns & reimpls for both the ECS and the mesh, incl. versions in Zig...

Not quite sure what your reference to Postgres is about in this context, but I'm intrigued. Are you thinking about massively detailed meshes and/or external storage of swathes of attribs/metadata?

thi.ng/ecsEntity Component System based around typed arrays & sparse sets
Continued thread

Reflecting some more on the Sketchpad & ECS parts of this talk: SideFX Houdini organizes all geometry data in similar vertical silos of points, vertices, edges, faces, prims, each with component IDs, each with its own group of native and user-defined attribs, and with similar powerful "omniscient" visibility/access from anywhere. That structure makes VEX SOPs akin to "systems" in an ECS setup and the handling/scripting itself very fun & powerful. The GUI also provides spreadsheet views of the geometry (again similar to e.g. what FLECS provides for debugging). Considering the age of Houdini, I think this approach is notable...

Blender's BMesh Radial Mesh implementation[1] is more traditional OOP structured, but the core idea of "discs" (aka bi-directional circular lists) of pointers to vertices & edges now seems somewhat relevant to some Sketchpad ideas too. Also a reminder that I really need to find/make time to update & release my own mesh implementation (from 2018) combining ideas from both Houdini & BMesh... It's already been a year (again) since I last talked about & touched it... 😱

[1] developer.blender.org/docs/fea

developer.blender.orgBMesh - Blender Developer Documentation

Watching "The Big OOPs", new 1h50m talk by Casey Muratori about the long and meandering history, mistakes & shortcomings of OOP and looking for better/alternative ways forward...

youtube.com/watch?v=wo84LFzx5n

(Also very interesting for some #PermaComputing & KISS aspects)

🚀 Looking for a hosting solution that balances power, security, and convenience?

Discover why Managed VPS Hosting is the top choice for professionals who demand performance, control, and peace of mind.

✅ Optimized performance
✅ Full root access (without the hassle)
✅ Expert support
✅ Enhanced security

Is it the right move for your business? Find out now! ⬇️

🔗 Read the full blog: bit.ly/44wiFLu