Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “resource control policies”

5 publications
Technical guideSource-based analysis

Stop S3 ransomware that encrypts objects with customer-provided keys

SSE-C ransomware rewrites S3 objects under a key only the attacker holds. AWS now blocks SSE-C by default on most buckets; this guide covers what that default misses and the controls that close the gap.

Detection & response · Amazon Web Services · By Cloud Security Desk
Technical guideSource-based analysis

Let AWS workloads call external services with IAM-issued tokens

IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.

Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Limit what Google Cloud principals can reach with principal access boundaries

Allow and deny policies sit on resources. A principal access boundary travels with the identity and limits which projects, folders and organizations it may touch, even where someone else granted it a role.

Identity & access · Google Cloud · By Cloud Security Desk
Research noteSource-based analysis

Place AWS guardrails on the principal and the resource

SCPs and RCPs constrain different sides of a request. A useful review records both the applicable guardrails and the policies that actually grant access.

Identity & access · AWS · By Cloud Security Desk
Research reportDesk publication

Qwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern

Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.

AI systems · Resilience · By Umair Akbar and Ahmed Elshekh