Karim El-Melhaoui (@karimscloud) 's Twitter Profile
Karim El-Melhaoui

@karimscloud

Principal Security Architect & Partner at o3c.no, CloudSec Researcher. Find me at bsky

ID: 793634400

linkhttps://blog.karims.cloud/ calendar_today31-08-2012 11:14:52

1,1K Tweet

818 Followers

695 Following

Karim El-Melhaoui (@karimscloud) 's Twitter Profile Photo

A client is hiring for a Security Engineer with cloud and product focus. The position is located in Oslo, Norway. They offer relocation, but EU/EAA working permit is required. jobs.remarkable.com/jobs/5163545-s…

hagaetc.eth (@hagaetc) 's Twitter Profile Photo

So I tried to build a tech company from Norway and here’s what happened: 1. Two years of building without almost any money/funding, better part of a year without salary 2. Raise VC and become one of Norway’s first unicorns 3. Face unrealized gains wealth tax bill of many x my

Karim El-Melhaoui (@karimscloud) 's Twitter Profile Photo

Spent some time on AWS research tonight. I’m looking forward to interact with the new vulnerability disclosure program 🫡

Scott Piper (@0xdabbad00) 's Twitter Profile Photo

AWS just released RCP examples to prevent OIDC misconfigurations from many third-party vendors. 😍 github.com/aws-samples/re… This prevents the problem I wrote about here: wiz.io/blog/avoiding-…

Wiz (@wiz_io) 's Twitter Profile Photo

🎙️ The podcast that CISOs share in their private channels is *back*! 🎊 Thank you to our guests for making the first 2 seasons incredible. This week: Amitai Cohen 🎗️🤟 & Eden Naftali chat with Karim El-Melhaoui on open-source dangers & stronger security standards. 🎧 Ready for S3?

🎙️ The podcast that CISOs share in their private channels is *back*! 🎊
Thank you to our guests for making the first 2 seasons incredible. 
This week: <a href="/AmitaiCo/">Amitai Cohen 🎗️🤟</a> &amp; Eden Naftali chat with <a href="/karimscloud/">Karim El-Melhaoui</a> on open-source dangers &amp; stronger security standards. 

🎧 Ready for S3?
Scott Piper (@0xdabbad00) 's Twitter Profile Photo

This looks like another security incident that may have been caused by "request collapsing". If you use AWS CloudFront, I encourage you to read an older blog post I wrote on this "feature" as it does something many don't expect. swedenherald.com/article/nordne… wiz.io/blog/preventin…

Liv Matan (@terminatorlm) 's Twitter Profile Photo

🏃‍♂️Meet ImageRunner: A privilege escalation vulnerability I discovered in GCP Cloud Run. Thank you for the Google VRP (Google Bug Hunters) team for working closely with us on this one. *Stay tuned for more blogs to come! tenable.com/blog/imagerunn…

Karim El-Melhaoui (@karimscloud) 's Twitter Profile Photo

Reminder that the fwd:cloudsec Europe 2025 Call for Papers is open! First time speakers who requested feedback by May 30th and meet the submission criteria will receive feedback on how to improve during the second round. For more: fwdcloudsec.org/conference/eur…

Karim El-Melhaoui (@karimscloud) 's Twitter Profile Photo

Great work by the SpecterOps team adding Entra ID to GitHub attack paths! Will officially archive once I can validate it supports OIDC github.com/O3-Cyber/oidc-…

fwd:cloudsec (@fwdcloudsec) 's Twitter Profile Photo

The schedule for fwd:cloudsec Europe is out, with a single track of high-quality talks over 2 days, along with “Birds of a Feather” interactive sessions! fwdcloudsec.org/conference/eur… Some sponsorship opportunities are still available