<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>HAIT | Cloud &amp; DevOps Blog</title><description>Technical articles on AWS, Terraform, CI/CD, Kubernetes, and cloud architecture.</description><link>https://haitmg.pl/</link><language>en-us</language><item><title>AWS Abuse Pattern Detection: 10 Open Source Signals (2026)</title><link>https://haitmg.pl/blog/aws-active-abuse-detection-threat-feed/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-active-abuse-detection-threat-feed/</guid><description>cloud-audit Threat Feed v1 - 10 open source detectors mapped to documented 2025-2026 AWS incidents. Confirmed signals, strong heuristics, precursors. CLI, MIT.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>threat-detection</category><category>open-source</category><category>cloud-audit</category><category>incident-response</category><category>ses</category><category>lambda</category><category>iam</category><category>bedrock</category></item><item><title>Prisma AIRS on Azure: 8 SCM gotchas from a working lab</title><link>https://haitmg.pl/blog/prisma-airs-azure-scm-gotchas/</link><guid isPermaLink="true">https://haitmg.pl/blog/prisma-airs-azure-scm-gotchas/</guid><description>Field notes from building Prisma AIRS Network Intercept in Azure under Strata Cloud Manager. 8 silent failures (PBF without UDR, Target Models trap) - with fixes.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>azure</category><category>palo-alto</category><category>prisma-airs</category><category>ai-security</category><category>scm</category><category>ssl-decryption</category><category>security</category><category>networking</category></item><item><title>K3s on AWS in 2026: 4 IAM auth methods benchmarked</title><link>https://haitmg.pl/blog/self-hosted-k3s-aws-auth-benchmark/</link><guid isPermaLink="true">https://haitmg.pl/blog/self-hosted-k3s-aws-auth-benchmark/</guid><description>Side-by-side benchmark of 4 AWS auth methods for self-hosted K3s: Instance Profile, IRSA-S3, IRSA-CloudFront, Roles Anywhere. Cold start, failures, cost.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>aws</category><category>kubernetes</category><category>k3s</category><category>iam</category><category>irsa</category><category>roles-anywhere</category><category>oidc</category><category>security</category><category>devops</category></item><item><title>5 AWS IAM Privesc Scanners vs 57 Paths: Coverage from 7% to 93%</title><link>https://haitmg.pl/blog/aws-iam-privesc-scanners-benchmark/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-iam-privesc-scanners-benchmark/</guid><description>I ran 5 OSS AWS IAM privesc scanners against 57 escalation paths. Coverage ranged from 7% to 93%. Full matrix, raw outputs, and per-tool caveats inside.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>aws</category><category>iam</category><category>security</category><category>oss-tools</category><category>privilege-escalation</category><category>benchmark</category></item><item><title>AWS Bedrock AgentCore: VPC Mode Still Leaks DNS After Unit 42 Disclosure</title><link>https://haitmg.pl/blog/aws-bedrock-agentcore-network-modes/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-bedrock-agentcore-network-modes/</guid><description>I lab-tested all three AWS Bedrock AgentCore network modes after Unit 42&apos;s April 7 disclosure. SANDBOX now isolated, VPC mode still leaks DNS - fix inside.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>aws</category><category>bedrock</category><category>agentcore</category><category>security</category><category>ai-agents</category><category>dns-firewall</category><category>vpc</category><category>cloud-security</category></item><item><title>12 Steps to Secure GitHub Actions After the Trivy Attack</title><link>https://haitmg.pl/blog/github-actions-security-after-trivy-attack/</link><guid isPermaLink="true">https://haitmg.pl/blog/github-actions-security-after-trivy-attack/</guid><description>What failed in the Trivy and tj-actions supply chain attacks. 12 concrete hardening steps with YAML and Terraform code for GitHub Actions pipelines.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>github-actions</category><category>supply-chain-security</category><category>aws</category><category>ci-cd</category><category>security</category><category>oidc</category></item><item><title>5 Open-Source AWS Security CLI Tools Worth Trying in 2026</title><link>https://haitmg.pl/blog/aws-security-cli-tools-2026/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-security-cli-tools-2026/</guid><description>Prowler, Trivy, CloudFox, Heimdall, and cloud-audit compared. What each does, where it falls short, and which one fits your workflow.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>open-source</category><category>devops</category><category>cloud-security</category><category>cli</category></item><item><title>Debugging AWS IAM and Privilege Escalation Using Multi-Model AI</title><link>https://haitmg.pl/blog/debugging-aws-iam-privilege-escalation-multi-model-ai/</link><guid isPermaLink="true">https://haitmg.pl/blog/debugging-aws-iam-privilege-escalation-multi-model-ai/</guid><description>How to debug IAM Access Denied errors, spot OIDC privilege escalation, and write Terraform fixes using multi-model AI consensus - querying multiple LLMs simultaneously to eliminate hallucinations.</description><pubDate>Sat, 28 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>iam</category><category>security</category><category>ai</category><category>terraform</category><category>devops</category><category>cloud-security</category></item><item><title>CIS AWS v3.0 in 60 Seconds: Automate Compliance with Terraform</title><link>https://haitmg.pl/blog/cis-aws-benchmark-automation/</link><guid isPermaLink="true">https://haitmg.pl/blog/cis-aws-benchmark-automation/</guid><description>Run a full CIS AWS Foundations Benchmark v3.0 assessment from your terminal. 62 controls, 55 automated, per-control Terraform remediation.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>compliance</category><category>cis-benchmark</category><category>terraform</category><category>devops</category><category>cloud-security</category><category>open-source</category></item><item><title>Prowler vs ScoutSuite vs cloud-audit: 572 Checks vs 94</title><link>https://haitmg.pl/blog/aws-security-scanners-compared/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-security-scanners-compared/</guid><description>One scanner runs 572 AWS checks. Another is unmaintained since May 2024. The third fits your CI with 94 curated checks. Real runs, not marketing.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>devops</category><category>open-source</category><category>cloud-security</category><category>prowler</category><category>scoutsuite</category><category>cloud-audit</category><category>cspm</category></item><item><title>The GitHub Actions OIDC Mistake That Backdoors Your AWS</title><link>https://haitmg.pl/blog/github-actions-oidc-aws-backdoor/</link><guid isPermaLink="true">https://haitmg.pl/blog/github-actions-oidc-aws-backdoor/</guid><description>One missing condition in your IAM trust policy exposes every role to any public GitHub repository. I found this in a live audit. Here is the one-line fix.</description><pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>github-actions</category><category>devops</category><category>oidc</category></item><item><title>AWS Cost Waste: 5 Things I Find in Every Audit</title><link>https://haitmg.pl/blog/aws-cost-waste-audit-findings/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-cost-waste-audit-findings/</guid><description>AWS cost waste averages 27-35% of cloud spend. 5 patterns I find in every audit: orphaned EBS, infinite CloudWatch retention, idle NAT Gateways, gp2 volumes, oversized RDS. CLI commands and Terraform fixes included.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>cost-optimization</category><category>terraform</category><category>devops</category><category>cloud-architecture</category></item><item><title>Palo Alto on AWS: 9 GWLB Pitfalls I Hit in Production</title><link>https://haitmg.pl/blog/palo-alto-vm-series-aws-transit-gateway-gwlb/</link><guid isPermaLink="true">https://haitmg.pl/blog/palo-alto-vm-series-aws-transit-gateway-gwlb/</guid><description>Three years of Palo Alto VM-Series with GWLB and Transit Gateway. 9 failure modes that cost billable hours: asymmetric routing, MTU, health checks.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>palo-alto</category><category>security</category><category>terraform</category><category>cloud-architecture</category></item><item><title>AWS Network Firewall: 0.59% Block Rate (CyberRatings)</title><link>https://haitmg.pl/blog/aws-network-firewall-security-test-results/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-network-firewall-security-test-results/</guid><description>Q1 2025 independent test: 12 of 2,028 exploits blocked by AWS Network Firewall. Zero against bypass techniques. Check Point and Palo Alto both above 99%.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>palo-alto</category><category>cloud-architecture</category></item><item><title>AWS Access Denied: 7 Policy Layers and a 60-Second Fix</title><link>https://haitmg.pl/blog/aws-iam-access-denied-debugging/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-iam-access-denied-debugging/</guid><description>Since January 2026, AWS names the exact policy ARN that blocked you. 7-layer evaluation order, STS decode command, and a debugging flowchart.</description><pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>iam</category><category>devops</category></item><item><title>AWS Network Firewall vs Palo Alto: 0.59% vs 99.6%</title><link>https://haitmg.pl/blog/aws-network-firewall-vs-palo-alto-vm-series/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-network-firewall-vs-palo-alto-vm-series/</guid><description>CyberRatings Q1 2025: AWS Network Firewall blocked 0.59% of 2,028 exploits. Palo Alto scored 99.6%. Full cost and detection comparison.</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>palo-alto</category><category>security</category><category>terraform</category><category>cloud-architecture</category></item><item><title>AWS Security Audit: 17 Issues in Every Account</title><link>https://haitmg.pl/blog/aws-security-audit-checklist/</link><guid isPermaLink="true">https://haitmg.pl/blog/aws-security-audit-checklist/</guid><description>Root without MFA, public RDS, 900-day-old keys. 17 AWS security misconfigurations I find in almost every account audit.</description><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate><category>aws</category><category>security</category><category>cloud-architecture</category><category>devops</category></item><item><title>Vulnerability Reports for Executives</title><link>https://haitmg.pl/blog/vulnerability-report-for-executives/</link><guid isPermaLink="true">https://haitmg.pl/blog/vulnerability-report-for-executives/</guid><description>89 CRITICAL CVEs in production, CEO wants a report by Friday. A framework for translating scan results into executive action.</description><pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate><category>security</category><category>vulnerability-management</category><category>kubernetes</category><category>devops</category><category>leadership</category></item><item><title>Terraform Variable Validation: 3 Copy-Paste Patterns</title><link>https://haitmg.pl/blog/terraform-module-validation/</link><guid isPermaLink="true">https://haitmg.pl/blog/terraform-module-validation/</guid><description>Validation blocks, preconditions, and postconditions. Three snippets you can drop into any Terraform module today. When each beats the others.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate><category>terraform</category><category>iac</category><category>aws</category><category>best-practices</category></item><item><title>Cloud Run SIGILL: Sapphire Rapids Broke llama.cpp AVX-512</title><link>https://haitmg.pl/blog/cloud-run-sigill-avx512-llama-cpp/</link><guid isPermaLink="true">https://haitmg.pl/blog/cloud-run-sigill-avx512-llama-cpp/</guid><description>Google silently swapped to Sapphire Rapids without AVX-512 runtime. llama.cpp crashed after 6 months working. The 20-second fix and how to detect it first.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate><category>cloud-run</category><category>debugging</category><category>llama-cpp</category><category>gcp</category><category>ai-infrastructure</category></item></channel></rss>