# Cloud Security Office Hours (CSOH) > CSOH is a vendor-neutral cloud security community. Free weekly Zoom (Fridays 7am PT), 2,000+ practitioners, 550+ curated resources. Static HTML site, no on-site ads, no cookies, no cross-site or marketing trackers; cookieless page-view analytics only (GoatCounter: the script is self-hosted at /vendor/goatcounter-count.js, the hosted service at csoh.goatcounter.com processes the counts; it records page path, page title, referrer, browser/OS and screen width, stores no IP address, and our patched copy strips the query string so site-search terms are never transmitted). (No sponsored content on the site or in the mailing list; hosting is offset by optional donations.) Founded 2023 by Shawn Nunley. The site collects practitioner-grade reference material on cloud security across AWS, Azure, GCP, Kubernetes, containers, serverless, IAM, AI/ML security, and detection engineering. All content is community-contributed and reviewed. Citations welcomed - every page declares an author, date, and canonical URL. JSON-LD schema (Article, FAQPage, HowTo, BreadcrumbList, Organization, Person) is present on most pages. The robots.txt explicitly allows GPTBot, ClaudeBot, PerplexityBot, Google-Extended, Applebot-Extended, CCBot and friends. ## Pillar guides - [What is Cloud Security?](https://csoh.org/what-is-cloud-security.html): A vendor-neutral introduction - shared responsibility, common threats, the CSPM/CNAPP/CWPP/CIEM tool landscape, and a learning roadmap. - [Cloud Security Learning Path](https://csoh.org/learning-path.html): Beginner → working practitioner. Roadmap, milestones, and labs. - [Cloud Security Best Practices](https://csoh.org/cloud-security-best-practices.html): The controls that actually prevent breaches - ranked by what shows up as root cause in real incident reports. - [The Shared Responsibility Model](https://csoh.org/shared-responsibility-model.html): What the cloud provider secures vs. what you secure across IaaS, PaaS, SaaS, and serverless. - [CSPM vs CNAPP vs CWPP vs CIEM vs DSPM](https://csoh.org/cspm-vs-cnapp.html): The acronym soup decoded. When you need each tool, where they overlap, and the open-source alternatives. - [Zero Trust Architecture](https://csoh.org/zero-trust.html): Practitioner-grade explanation of Zero Trust in cloud. - [Cloud Landing Zones](https://csoh.org/landing-zones.html): Multi-account org structure, baseline guardrails, centralized logging. ## Provider-specific guides - [AWS Security - The Complete Guide](https://csoh.org/aws-security.html) - [Azure Security](https://csoh.org/azure-security.html) - [GCP Security](https://csoh.org/gcp-security.html) - [Kubernetes & Managed Kubernetes Security](https://csoh.org/kubernetes.html) - [Container Security](https://csoh.org/containers.html) - [Serverless Security](https://csoh.org/serverless.html) ## Topic guides - [IAM & Cloud Identity](https://csoh.org/iam.html) - [Cloud Data Security](https://csoh.org/data-security.html) - [Cloud Network Security](https://csoh.org/network-security.html) - [API Security](https://csoh.org/api-security.html) - [SaaS Security](https://csoh.org/saas-security.html) - [AI/ML Security](https://csoh.org/ai-ml-security.html) - [Service Mesh Security](https://csoh.org/service-mesh-security.html) - [Vulnerability Management](https://csoh.org/vulnerability-management.html) - [Threat Modeling](https://csoh.org/threat-modeling.html) - [Detection Engineering](https://csoh.org/detection-engineering.html) - [Cloud Threat Research](https://csoh.org/threat-research.html): IOC feeds, MITRE ATT&CK Cloud mappings, vendor research teams. - [Cloud Incident Response](https://csoh.org/incident-response.html) - [Cloud SOC & Threat Monitoring](https://csoh.org/cloud-soc.html) - [Cloud Pentesting](https://csoh.org/cloud-pentesting.html) - [CI/CD Security](https://csoh.org/ci-cd.html) - [GitHub Actions security](https://csoh.org/github-actions.html) - [Terraform / Infrastructure as Code](https://csoh.org/terraform.html): IaC explained through our real multi-cloud Terraform, with a security focus (state, keyless OIDC, least privilege). - [Git & Version Control](https://csoh.org/version-control.html): version control from first principles plus our real git/PR workflow and keeping secrets out of history. - [GRC for Cloud](https://csoh.org/grc.html) - [Compliance Frameworks](https://csoh.org/compliance-frameworks.html) - [Backup & Disaster Recovery](https://csoh.org/backup-dr.html) - [Cloud Deployment Patterns](https://csoh.org/cloud-deployment.html) - [How csoh.org Is Secured](https://csoh.org/how-csoh-org-is-secured.html) - [Non-Human Identity (NHI) Security](https://csoh.org/non-human-identity.html) - [MCP Security](https://csoh.org/mcp-security.html) - [CNAPP vs XDR](https://csoh.org/cnapp-vs-xdr.html) - [CSPM vs CWPP](https://csoh.org/cspm-vs-cwpp.html) - [Lessons From 45 Cloud Breaches](https://csoh.org/breach-lessons.html) - [Vendor Landscape](https://csoh.org/vendor-landscape.html) ## Reference - [Cloud Security Glossary](https://csoh.org/glossary.html): 320+ terms in plain English. - [Cloud Security FAQ](https://csoh.org/faq.html) - [Cloud Security News](https://csoh.org/news.html): Curated daily from 62 vendor-neutral sources. Also as [RSS](https://csoh.org/feed.xml). - [Cloud Breach Kill Chains](https://csoh.org/breach-timeline.html): Step-by-step attack reconstructions mapped to MITRE ATT&CK Cloud - Capital One, event-stream npm backdoor, SolarWinds, Log4Shell (CVE-2021-44228), ChaosDB / Azure Cosmos DB, Kaseya VSA / REvil, Codecov Bash Uploader, Okta / LAPSUS$, 0ktapus / Twilio, CircleCI, LastPass, 3CX / X_TRADER cascading compromise, MGM, Okta support system HAR files, Snowflake, Storm-0558, Uber, Microsoft SAS Leak, Promptware, MOVEit / Cl0p (CVE-2023-34362), Midnight Blizzard, Change Healthcare, Polyfill.io, XZ Utils (CVE-2024-3094), Ultralytics cache poisoning, Mitnick/Novell, Codefinger S3 SSE-C ransomware, tj-actions/changed-files (CVE-2025-30066), Salesloft Drift / UNC6395, UNC6040 Salesforce vishing, Entra ID Actor token (CVE-2025-55241), SharePoint ToolShell (CVE-2025-53770), Nx / s1ngularity, npm debug / chalk, Shai-Hulud npm worm, Oracle EBS / Cl0p (CVE-2025-61882), GTG-1002 AI-orchestrated espionage, LiteLLM PyPI / TeamPCP, Vercel / Context.ai OAuth, Vimeo / Anodot, Mini Shai-Hulud / TanStack, Megalodon GitHub Actions, Storm-2949 Entra ID SSPR, the suspected AI-assisted AWS compromise, and the Hugging Face / OpenAI agent breach. - [Cloud Breach Year in Review](https://csoh.org/cloud-breach-year-in-review.html): The series hub - one review per year from 2021 to 2026, drawn from the 45 kill chains. - [2026 Cloud Breaches: The First Half](https://csoh.org/cloud-breach-year-in-review-2026-h1.html): Mid-year review - AI agents as attackers, the AI toolchain as target, supply-chain attacks routing around provenance. - [2024 Cloud Breach Year in Review](https://csoh.org/cloud-breach-year-in-review-2024.html): XZ Utils, Snowflake, Change Healthcare, Midnight Blizzard, Polyfill.io, Ultralytics. - [2023 Cloud Breach Year in Review](https://csoh.org/cloud-breach-year-in-review-2023.html): MOVEit, 3CX, Storm-0558, MGM, the Okta support system, CircleCI. - [2021-2022 Cloud Breach Review](https://csoh.org/cloud-breach-year-in-review-2021-2022.html): Log4Shell, Codecov, Kaseya, ChaosDB, Okta/LAPSUS$, Uber, 0ktapus. - [2025 Cloud Breach Year in Review](https://csoh.org/cloud-breach-year-in-review-2025.html): The cloud, SaaS, and supply-chain incidents that defined 2025 (Codefinger, tj-actions, Salesloft Drift, npm worms, Entra Actor-token, Oracle EBS, SharePoint ToolShell) and what they mean for 2026. ## Career & learning - [Cloud Security Careers](https://csoh.org/cloud-security-careers.html) - [Cloud Security Interview Questions (with model answers)](https://csoh.org/cloud-security-interview-questions.html) - [The Cloud Security Resume Guide](https://csoh.org/cloud-security-resume-guide.html) - [Breaking Into Cloud Security](https://csoh.org/breaking-into-cloud-security.html): Whether it is a good career, whether you can start with no experience, and the path from where you are now to hired. Consolidates three earlier entry-path guides. - [Mentorship at CSOH](https://csoh.org/mentorship.html): How peer mentorship naturally happens between experts and newcomers in the Friday Zoom, Signal chat, and via LinkedIn. - [Cloud Security Certifications](https://csoh.org/cloud-security-certifications.html): CCSK, CCSP, AWS, Azure, GCP, CKS. - [Cloud Security Degree Programs](https://csoh.org/cloud-security-degree-programs.html) - [Cloud Security Home Lab](https://csoh.org/cloud-security-home-lab.html) - [Cloud Security Portfolio Projects](https://csoh.org/cloud-security-portfolio-projects.html): 7 hands-on portfolio projects. - [Cloud Security Reading List](https://csoh.org/cloud-security-reading-list.html) - [AI Learning Path](https://csoh.org/ai-learning.html) - [Cloud Security CTF Challenges](https://csoh.org/ctfs.html) - [Security & Hacker Conferences](https://csoh.org/conferences.html) ## Community - [About Shawn Nunley](https://csoh.org/about-shawn-nunley.html): Founder, CSOH; Solutions Architect at Wiz. - [Weekly Zoom Sessions](https://csoh.org/sessions.html): Fridays 7am PT. - [Meeting Recaps Archive](https://csoh.org/meetings.html): 110+ weekly sessions, searchable by speaker and topic. - [Past Talks](https://csoh.org/presentations.html) - [Guest Speakers](https://csoh.org/speakers.html) - [Present at CSOH](https://csoh.org/present.html): How to pitch a talk. - [Resources Directory](https://csoh.org/resources.html): 550+ curated tools, CTFs, courses, labs. - [Contribute](https://csoh.org/contribute.html) ## Optional - [Sitemap](https://csoh.org/sitemap.xml) - [RSS feed](https://csoh.org/feed.xml) - [Code of Conduct](https://csoh.org/code-of-conduct.html) - [Privacy](https://csoh.org/privacy.html) - no cookies, no cross-site or marketing trackers, no marketing pixels; cookieless page-view analytics only. - [Security disclosure](https://csoh.org/security-policy.html)