Feed
Upwind Feed
Feed
Grid
research

October 8, 2026
CVE-2026-21589: Unauthenticated Arbitrary File Read in Atlassian Data Center Suite
On October 5, 2026, Atlassian issued an emergency out-of-band security advisory for CVE-2026-21589, a critical vulnerability impacting eight self-hosted Atlassian Data Center and Server product suites - including Jira Software, Confluence, Bitbucket, Jira Service Management, Bamboo, Crowd, Fisheye, and Crucible. The flaw allows an unauthenticated remote attacker to read sensitive internal files within the application's…

October 6, 2026
Agent Skill Risks: Taxonomy 101
Introduction In the first eight months of 2026, a Russian-speaking threat actor who had built a career on hotel-booking and fintech platforms turned to AI companies. The technique they used against one AI vendor did not involve any exploit. Like most AI vendors, the target ran an automated evaluation sandbox, an agent pipeline that reads…

September 25, 2026
What IAM Sees That You Don’t
Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…

September 25, 2026
Let Me Speak to Your Manager (Account)
The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…

September 23, 2026
What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys
In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…

September 23, 2026
Show Me the Context: Building the Full Request Context for AWS IAM
This post was written in early August 2026, ahead of our fwd:cloudsec Europe talk. On August 25, AWS launched the Access Troubleshooter (currently in public preview), a first-party feature that surfaces the request context for denied requests. We've updated this post to account for it. When the IAM engine evaluates your request, it matches your…

September 16, 2026
What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part III
Recap In Part I and Part II, we: Networking and VPC Mode Network Isolation Testing The microVM is assigned an IPv6 address matching the value in the JWT. Across multiple runs, all addresses shared the same 2600:1f18::/32 prefix, but cross-microVM communication always failed. We attempted to reach the host EC2 IMDS by manipulating the route…

September 14, 2026
What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part I
Introduction When you deploy an AI agent to AWS Bedrock AgentCore Runtime, your code runs inside a Firecracker microVM - but it doesn't run alone. In this three-part series, we tear down the platform internals, document what we found, and assess how well the isolation holds up. Setting the Stage AWS Bedrock AgentCore Runtime is…

August 24, 2026
ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover
Executive Summary This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…

July 14, 2026
No npm Token Required: Inside the AsyncAPI Supply Chain Attack
Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…

June 5, 2026
From “Encrypt Everything” to “Encrypt for the Quantum Era”: The Upwind Cloud Cryptography Framework
For most of the last decade, cloud security teams have lived by a simple slogan: encrypt everything. Encrypt at rest. Encrypt in transit. Use customer-managed keys. Rotate them. Pass the audit. Move on. That slogan just expired. In August 2024, NIST finalized the first three post-quantum cryptography (PQC) standards and explicitly told organizations: start using…

June 4, 2026
Miasma: A Worming npm Supply Chain Attack on Red Hat Cloud Services
Executive Summary On June 1, 2026, unauthorized commits were pushed to repositories in the RedHatInsights GitHub organization and used to publish malicious versions of 32 packages under the @redhat-cloud-services npm scope.The campaign, tracked as Miasma, executes a 4.2 MB obfuscated payload through an npm preinstall hook the moment any of these packages is installed, directly…

CVE-2026-21589: Unauthenticated Arbitrary File Read in Atlassian Data Center Suite
On October 5, 2026, Atlassian issued an emergency out-of-band security advisory for CVE-2026-21589, a critical vulnerability impacting eight self-hosted Atlassian Data Center and Server product suites - including Jira Software, Confluence, Bitbucket, Jira Service Management, Bamboo, Crowd, Fisheye, and Crucible. The flaw allows an unauthenticated remote attacker to read sensitive internal files within the application's…

Agent Skill Risks: Taxonomy 101
Introduction In the first eight months of 2026, a Russian-speaking threat actor who had built a career on hotel-booking and fintech platforms turned to AI companies. The technique they used against one AI vendor did not involve any exploit. Like most AI vendors, the target ran an automated evaluation sandbox, an agent pipeline that reads…

What IAM Sees That You Don’t
Every IAM policy you write depends on condition keys - they're the precision layer that turns "can call S3" into "can call S3 only from our VPC, using our identity, on resources we own." They're the backbone of least-privilege, data perimeters, and SCP guardrails. But here's the thing: for every request, the IAM engine assembles…

Let Me Speak to Your Manager (Account)
The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys
In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…

Show Me the Context: Building the Full Request Context for AWS IAM
This post was written in early August 2026, ahead of our fwd:cloudsec Europe talk. On August 25, AWS launched the Access Troubleshooter (currently in public preview), a first-party feature that surfaces the request context for denied requests. We've updated this post to account for it. When the IAM engine evaluates your request, it matches your…

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part III
Recap In Part I and Part II, we: Networking and VPC Mode Network Isolation Testing The microVM is assigned an IPv6 address matching the value in the JWT. Across multiple runs, all addresses shared the same 2600:1f18::/32 prefix, but cross-microVM communication always failed. We attempted to reach the host EC2 IMDS by manipulating the route…

What’s Behind the Curtain? AWS Bedrock AgentCore Runtime Tear Down – Part I
Introduction When you deploy an AI agent to AWS Bedrock AgentCore Runtime, your code runs inside a Firecracker microVM - but it doesn't run alone. In this three-part series, we tear down the platform internals, document what we found, and assess how well the isolation holds up. Setting the Stage AWS Bedrock AgentCore Runtime is…

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover
Executive Summary This stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.4] allows an attacker who can create or modify an Application to persist a malicious repoURL, which is subsequently executed in an administrator's browser within the Argo CD origin. Because the payload executes in the context of the administrator's authenticated session, and because…

No npm Token Required: Inside the AsyncAPI Supply Chain Attack
Executive Summary Upwind identified a critical supply chain compromise across five npm packages in the @asyncapi scope, published on July 14, 2026 via two separate branch compromises in two GitHub repositories. The attacker never touched an npm token. They abused each project's own CI pipeline through GitHub Actions OIDC to publish the malicious packages. The…

From “Encrypt Everything” to “Encrypt for the Quantum Era”: The Upwind Cloud Cryptography Framework
For most of the last decade, cloud security teams have lived by a simple slogan: encrypt everything. Encrypt at rest. Encrypt in transit. Use customer-managed keys. Rotate them. Pass the audit. Move on. That slogan just expired. In August 2024, NIST finalized the first three post-quantum cryptography (PQC) standards and explicitly told organizations: start using…

Miasma: A Worming npm Supply Chain Attack on Red Hat Cloud Services
Executive Summary On June 1, 2026, unauthorized commits were pushed to repositories in the RedHatInsights GitHub organization and used to publish malicious versions of 32 packages under the @redhat-cloud-services npm scope.The campaign, tracked as Miasma, executes a 4.2 MB obfuscated payload through an npm preinstall hook the moment any of these packages is installed, directly…