<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cloud Security — Things Worth Sharing</title><description>Bài viết gắn tag Cloud Security.</description><link>https://cloudsecop.net/</link><item><title>Remote SWE agents: autonomous coding với AWS Strands Agents</title><link>https://cloudsecop.net/blog/aws-remote-swe-agents-strands/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-remote-swe-agents-strands/</guid><description>AWS Strands Agents + Bedrock AgentCore cho autonomous SWE agent. GitHub issue → PR. Threat model, IAM blast radius, audit. So sánh Copilot Workspace và Devin.</description><pubDate>Mon, 12 Jan 2026 00:00:00 GMT</pubDate><category>AWS</category><category>Bedrock</category><category>AI Agents</category><category>DevOps</category><category>Cloud Security</category><author>KhaVan</author></item><item><title>AWS Well-Architected custom lens: build riêng cho cloud security ở scale</title><link>https://cloudsecop.net/blog/aws-well-architected-custom-lens/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-well-architected-custom-lens/</guid><description>Custom lens AWS Well-Architected: thêm pillar riêng cho org, JSON schema, deploy CloudFormation, attach workload. Use case Vietnam compliance Circular 09, Decree 53.</description><pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Governance</category><category>Well-Architected</category><category>Architecture</category><author>KhaVan</author></item><item><title>AWS Security Services Best Practices: đọc cuốn cẩm nang mới</title><link>https://cloudsecop.net/blog/aws-security-services-best-practices/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-services-best-practices/</guid><description>AWS vừa publish best-practices guide cho 10 dịch vụ bảo mật (GuardDuty, Security Hub, Macie, Inspector, WAF, Network Firewall). Cấu trúc guide và lộ trình triển khai thực tế.</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Hub</category><category>Best Practices</category><author>KhaVan</author></item><item><title>AWS Security Maturity Model v2: 4 phase áp dụng thực tế</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-v2/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-v2/</guid><description>AWS Security Maturity Model v2: 74 kiểm soát chia 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized), thứ tự nên làm, bẫy thường gặp, ánh xạ vào Organization.</description><pubDate>Sun, 27 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Governance</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Bedrock từ Workers qua OIDC federation — case study production</title><link>https://cloudsecop.net/blog/bedrock-workers-oidc-case-study/</link><guid isPermaLink="true">https://cloudsecop.net/blog/bedrock-workers-oidc-case-study/</guid><description>Worker mint RS256 JWT → STS AssumeRoleWithWebIdentity → Bedrock Claude Opus. Số liệu thực: token 5ms, STS 200ms, Bedrock 2-3s, cached 50ms.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Workers</category><category>AWS</category><category>Bedrock</category><category>OIDC</category><category>Cloud Security</category><author>KhaVan</author></item><item><title>AWS SMM Assessment Tool: đánh giá posture trong một chiều</title><link>https://cloudsecop.net/blog/aws-security-maturity-model-assessment-tool/</link><guid isPermaLink="true">https://cloudsecop.net/blog/aws-security-maturity-model-assessment-tool/</guid><description>Ghi chú dùng AWS Security Maturity Model Assessment Tool đánh giá posture theo 4 giai đoạn (Quick Wins, Foundational, Efficient, Optimized): kiến trúc, quy trình, JSON/Excel.</description><pubDate>Sun, 20 Jul 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>Security Maturity</category><category>Assessment</category><category>Governance</category><author>KhaVan</author></item><item><title>hardeneks: EKS security checks ở CI vs sau-deploy</title><link>https://cloudsecop.net/blog/hardeneks-eks-security/</link><guid isPermaLink="true">https://cloudsecop.net/blog/hardeneks-eks-security/</guid><description>hardeneks là Python CLI chạy 100+ EKS best-practice check. Lý do tôi chạy ở PR thay vì weekly cron, so sánh kube-bench/kube-hunter, finding thực tế.</description><pubDate>Wed, 04 Jun 2025 00:00:00 GMT</pubDate><category>AWS</category><category>EKS</category><category>Kubernetes</category><category>Cloud Security</category><category>Compliance</category><author>KhaVan</author></item><item><title>AWS KMS Key Policies: hiểu đúng để không mất quyền truy cập</title><link>https://cloudsecop.net/blog/kms-key-policies-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/blog/kms-key-policies-deep-dive/</guid><description>Cơ chế evaluation của KMS key policy, cross-account access, condition keys, grants, key rotation, production patterns. Kèm JSON policy examples và checklist cho production.</description><pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>KMS</category><category>Encryption</category><category>IAM</category><author>KhaVan</author></item><item><title>GuardDuty auto-remediation: cô lập EC2 và thu hồi IAM</title><link>https://cloudsecop.net/blog/guardduty-auto-remediation/</link><guid isPermaLink="true">https://cloudsecop.net/blog/guardduty-auto-remediation/</guid><description>Pipeline tự động phản ứng sự cố bảo mật với GuardDuty, EventBridge và Lambda: cô lập instance, snapshot forensic, thu hồi credentials, mở rộng multi-account với Organizations.</description><pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate><category>AWS</category><category>Cloud Security</category><category>GuardDuty</category><category>Security Automation</category><category>EventBridge</category><author>KhaVan</author></item><item><title>Flan: vulnerability scanner Cloudflare dùng trong production</title><link>https://cloudsecop.net/blog/flan-vulnerability-scanner/</link><guid isPermaLink="true">https://cloudsecop.net/blog/flan-vulnerability-scanner/</guid><description>Flan wrap nmap NSE + Vulners API trong Docker, xuất HTML/JSON. Vì sao Cloudflare tự host thay vì mua Tenable/Qualys, và cách integrate vào CI gate CVE.</description><pubDate>Wed, 12 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Security</category><category>Vulnerability Management</category><category>Cloud Security</category><category>DevSecOps</category><author>KhaVan</author></item><item><title>Đọc lại roadmap.sh Cyber Security 2026: góc nhìn cloud sec</title><link>https://cloudsecop.net/blog/roadmap-sh-cyber-security-goc-nhin/</link><guid isPermaLink="true">https://cloudsecop.net/blog/roadmap-sh-cyber-security-goc-nhin/</guid><description>roadmap.sh chia con đường cyber security thành 6 khối kỹ năng. Đọc lại đối chiếu với cloud security và Zero Trust, chỗ đúng, chỗ đã cũ, và thứ tự học nếu bắt đầu lại hôm nay.</description><pubDate>Wed, 19 Feb 2025 00:00:00 GMT</pubDate><category>Security</category><category>Roadmap</category><category>Learning Path</category><category>Cloud Security</category><category>Career</category><author>KhaVan</author></item><item><title>Workload Identity Federation AWS sang GCP: keyless auth</title><link>https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</link><guid isPermaLink="true">https://cloudsecop.net/blog/workload-identity-federation-aws-gcp/</guid><description>Workload Identity Federation deep dive: vì sao Service Account Key là anti-pattern, luồng token AWS STS → Google STS, attribute mapping, impersonation, threat model, Terraform.</description><pubDate>Mon, 27 Jan 2025 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>GCP</category><category>Identity Federation</category><category>Multi-Cloud</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Chạy CSPM trên hơn chục AWS Landing Zone</title><link>https://cloudsecop.net/blog/cspm-across-multiple-landing-zones/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cspm-across-multiple-landing-zones/</guid><description>Cách mình thiết kế CSPM engine nội bộ quét song song nhiều AWS Landing Zone bằng Prowler, lưu finding vào D1, artifact vào R2, dashboard duy nhất cho Security Operations.</description><pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate><category>Cloud Security</category><category>AWS</category><category>CSPM</category><category>Prowler</category><category>Cloudflare</category><author>KhaVan</author></item><item><title>CFSSL trong production — Cloudflare&apos;s PKI toolkit cho internal CA</title><link>https://cloudsecop.net/blog/cfssl-pki-toolkit-production/</link><guid isPermaLink="true">https://cloudsecop.net/blog/cfssl-pki-toolkit-production/</guid><description>Tự host internal CA bằng CFSSL: cfssl init, intermediate CA, OCSP responder, multirootca, CI short-lived certs. So sánh AWS Private CA $400/tháng.</description><pubDate>Fri, 15 Nov 2024 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloud Security</category><category>PKI</category><category>TLS</category><category>Certificates</category><author>KhaVan</author></item></channel></rss>