frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Cloud-audit – AWS scanner that chains findings into attack paths

https://github.com/gebalamariusz/cloud-audit
3•gebalamariusz•1h ago

Comments

gebalamariusz•1h ago
I decided to create this tool for more pragmatic reasons. First, I've been at AWS for several years now, and security has always been a major issue in many companies I've worked for. Second, even if you're a specialist with a memory like a movie's mind, you can't manually check every corner of your environment to realistically assess whether a real problem exists. Third, existing scanners are great, but they're full of noise, and I suspect you know what such an "audit" looks like. You open a report, see that your account has 300+ findings, review the first ten, which turn out to be insignificant, and then dismiss the report. Here, I wanted to focus on truly realistic scenarios (although I suspect there's still a lot to refine).

That's why I didn't focus on an incredible number of checks, but rather on the correlation between them. Something like a vulnerability based on findings (Public Security Group with port 22 -> IMDSv1 -> IAM Roles on EC2 with high access), which individually might not seem dangerous, but when combined, they create a real opportunity for attackers. Taking a bit of inspiration from other scanners, I've also added an option to automatically fix the issue (of course, this is just a hint on how to do it, but it's always more convenient to get a ready-made Terraform snippet instead of searching for fixes in the documentation).

I still have a lot of ideas for developing this, so I'd like to show you what it looks like now and would love to hear your feedback on whether you think it makes sense or whether tools like Prowler have already completely covered this sector in terms of security. I've recently added CIS 3.0 and SOC 2 compliance reports. This isn't SaaS—it's completely open source with the simplest possible installation. Documentation is available on the repo.

If you have any questions or ideas, I would be extremely grateful for each one.

iOS 18 security update for all iPhone users

https://9to5mac.com/2026/04/01/apple-releases-ios-18-security-update-for-all-iphone-users-update-...
1•qaz_plm•2m ago•0 comments

Copyright Industry Continues Its Efforts to Ban VPNs

https://www.techdirt.com/2026/04/01/copyright-industry-continues-its-efforts-to-ban-vpns/
1•duringmath•2m ago•0 comments

Dynamic Island for Your Agents

https://vibeisland.app/
1•nnx•2m ago•0 comments

Functional programming is the simplest way to scale agentic development

https://cyrusradfar.com/thoughts/functional-programming-is-the-only-way-to-scale-with-ai
2•cyrusradfar•3m ago•0 comments

Spotify takes on its doppelgänger problem

https://www.platformer.news/spotify-artist-profile-protection/
3•ilamont•5m ago•0 comments

Claude Dispatch and the Power of Interfaces

https://www.oneusefulthing.org/p/claude-dispatch-and-the-power-of
2•nadis•5m ago•0 comments

Show HN: Canon PIXMA G3010 macOS driver, reverse-engineered with Claude

https://github.com/pdrgds/pixma-rs
1•pdrgds•6m ago•0 comments

Warrior Dashboard – self-improvement tracker that works like an RPG

https://warrior-dashboard.onrender.com/auth/login?next=%2F
1•Vener•7m ago•0 comments

Apple became Apple:The definitive oral history of the company's earliest day

https://www.fastcompany.com/91514404/apple-founding-50th-anniversary-apple-1-apple-ii-jobs-wozniak
1•sanj•8m ago•0 comments

US FDA Expected to Lift Restrictions on Dozen Peptides Previously Banned

https://www.nytimes.com/2026/03/31/health/peptide-ban-fda-rfk-jr.html
2•ck2•10m ago•0 comments

Ask HN: What is your advice to current CS students?

1•aavci•11m ago•1 comments

Engine Cinema. OpenAI Killed Sora to Build a Cinema Camera

https://ymcinema.com/2026/04/01/openai-engine-cinema-square-sensor-camera/
1•bahmboo•11m ago•1 comments

I replaced one AI agent with a mesh of specialists. Here's what changed

https://kinarey.com/the-mesh/
1•indynz•11m ago•1 comments

Modernize Your Punch Card Review with Review Board

https://www.reviewboard.org/punch-cards/
1•chipx86•12m ago•0 comments

How come American manufacturing doesn't use social media effectively?

2•hammerbrostime•14m ago•1 comments

AI Let Me Be the Engineer I've Always Wanted to Be

https://www.builtbyvibes.com/#blog/ai-let-me-be-the-engineer
1•watkajtys•14m ago•0 comments

"Claude, add that to my notes" – simple iOS notes app your agent can edit

https://northbase-website.vercel.app/
1•edbern•16m ago•0 comments

What IAEA docs say about Iran's nuclear program, before the bombs fell

https://meetdewey.com/blog/iaea-iran-nuclear-reports
13•lambdabaa•18m ago•4 comments

Elon Musk: We're going straight to Mars. The Moon is a distraction. (2025)

https://twitter.com/elonmusk/status/1875023335891026324
1•simonebrunozzi•19m ago•0 comments

OpenAI Is Almost Public

https://www.bloomberg.com/opinion/newsletters/2026-04-01/openai-is-almost-public
1•toomuchtodo•20m ago•1 comments

Show HN: Hire Gnome – a lightweight ATS for small recruiting agencies

https://hiregnome.com/
1•harrywynn•20m ago•0 comments

Israel's Message to a Broad Swath of Lebanon: Shiites Must Go

https://www.nytimes.com/2026/04/01/world/middleeast/lebanon-shiite-israel-evacuation.html
5•ceejayoz•24m ago•0 comments

Varen – monitor API changes before they break your integration

https://varen.dev
1•skyatday•24m ago•1 comments

Renewable energy hits record growth as war boosts sector focus

https://www.thenationalnews.com/business/energy/2026/04/01/renewable-energy-capacity-in-record-ri...
1•01-_-•26m ago•0 comments

JavaScript devs, we hear you

https://adonisjs.com/we-hear-you
1•gherkinnn•27m ago•0 comments

Amazon's cloud business in Bahrain damaged in Iran strike

https://www.reuters.com/world/middle-east/amazons-cloud-business-bahrain-damaged-iran-strike-ft-r...
5•01-_-•28m ago•0 comments

TurboQuant KV Compression and SSD Expert Streaming for M5 Pro and IOS

https://github.com/SharpAI/SwiftLM
4•aegis_camera•29m ago•0 comments

Game Pirates Beat Denuvo with Hypervisor Bypasses

https://torrentfreak.com/game-pirates-beat-denuvo-with-hypervisor-bypasses-irdeto-promises-counte...
2•Cider9986•29m ago•0 comments

Show HN: Computerpoker.ai – Learn GTO tournament poker strategy vs. GTO bots

https://computerpoker.ai
1•abbadadda•31m ago•0 comments

Emissions trading with clean-up certificates to increase climate ambition levels

https://www.sciencedirect.com/science/article/pii/S0095069626000276
1•PaulHoule•31m ago•0 comments