Results for "Cloud security"
- Article
Cloud-Native Security Platform: A Complete Guide
A complete guide to cloud-native security platforms. Learn CNAPP components, CSPM, CWPP, CIEM, KSPM, and how to secure your cloud stack against modern threats.
- Article
How Broken Access Controls in Cal.com Leaked Millions of Bookings and Enabled Complete Account Takeover
Gecko’s AI security engineer discovered critical chained vulnerabilities in Cal.com Cloud that allowed complete account takeover and exposed all booking data.
- Page
Terms of Service
The Cloud Service Agreement governing use of the Gecko Security site and cloud services: access and use, restrictions, payment, warranties, liability and disput…
- Article
What Is SSRF (Server-Side Request Forgery)? A Complete Guide
Learn what SSRF (Server-Side Request Forgery) is, how attackers exploit it in cloud environments, and proven defense strategies. A complete guide.
- Article
CVE-2025-54381: BentoML SSRF in File Upload Processing
Server-side request forgery vulnerability in BentoML’s file upload processing system allowing arbitrary HTTP requests from the server.
- Article
CVE-2026-21894: n8n Missing Stripe-Signature Verification Allows Forged Webhooks
Authentication bypass in n8n’s StripeTrigger node allows unauthenticated attackers to forge arbitrary Stripe webhooks without knowing the signing secret.
- Article
SSRF in File Upload Processing: Complete Prevention Guide
Learn how SSRF in file upload processing bypasses security through ImageMagick and PDF renderers. A complete prevention guide.
- Article
CVE-2026-25055: n8n Arbitrary File Write on Remote Systems via SSH Node
Path traversal vulnerability in n8n’s Webhook node allows attackers to write files to arbitrary locations on remote servers connected via SSH.
- Article
RCE in Your Test Suite: AI Agent Skills and the Attack Vector Skill Scanners Miss
When a developer runs npx skills add, the installer copies the entire skill directory into the repo. If a malicious skill includes a *.test.ts file, it runs dur…
- Article
Business Logic Is AppSec’s Unsolved Problem
Broken access control has been the #1 vulnerability class since 2021. This post explores why it’s unsolved, why it will get worse, and how LLMs can bridge the g…
Showing 1 - 10 of 10 results