Urgent.News

What's breaking now, across thousands of outlets.

Tech

57 Findings Across 12 AWS Services. Zero False Positives. No Credentials Required.

✓ Human-authored analysis; AI used for formatting and proofreading. NCC Group built SadCloud to test cloud security tools. It deploys intentionally vulnerable AWS infrastructure with 84 misconfigurations across 22 services so you can measure exactly what your scanner catches and what it misses. We pointed a static analyzer at a SadCloud deployment. It does not use credentials or make API calls…

NCC Group developed a tool called SadCloud to evaluate cloud security tools by deploying intentionally vulnerable AWS infrastructure with 84 misconfigurations across 22 services. Using a static analyzer, 57 findings were identified across 12 AWS services without requiring any credentials or API calls against the live environment.

The analyzer found 57 issues in four iterations, each time fixing identified gaps. The findings are categorized into critical, high, medium, and low/Info severity. The most significant finding is a chain of events where CloudWatch detection is broken, specifically the detection pipeline being broken at the metric-filter, alarm, or alarm-action layer, rendering any monitoring ineffective.

This blind spot is not typically detected by individual-check scanners, highlighting the importance of evaluating the composition of security measures rather than just their individual settings.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Conflicting Android beta reports: separating observations from verified bugs

Two reports from a small Android beta described different behaviour for the same breathing timer: one tester said it restarted after switching apps, while another said it resumed correctly.

  • Breathing timer restarts after app switch on Android 15 beta.
  • Money-saved widget value matches only after manual refresh.
  • Follow-up test plan proposed to investigate issues.

PDF to Excel in the Browser: Extracting Tables with JavaScript

Series: Building PdfWord — a free, no-backend PDF tools site (Part 11) "Convert my bank statement PDF to Excel" — one of the most requested features I've gotten, and one of the most technically…

  • JavaScript extracts positioned text from PDFs using page.getTextContent() method
  • GroupLines() algorithm reconstructs lines by sorting fragments by y-coordinate and x-coordinate
  • SheetJS converts lines to spreadsheet format for Excel file export

How I Made PdfWord Work Fully Offline as a PWA

Series: Building PdfWord — a free, no-backend PDF tools site (Part 10) Most "free PDF tools" die the moment your Wi-Fi does.

  • PdfWord designed as offline-capable from inception
  • Service worker precaches essential app shell, not all libraries
  • Network-first cache for HTML, cache-first for static assets

Backtesting a Polymarket copy trading bot without fooling yourself

Copy trading is the most common bot idea on Polymarket: find the wallets that win and buy what they buy. We tested it on five sports (MLB, NFL, college football, League of Legends and Valorant) and it…

  • Copy trading bots showed no profitability across five sports in backtest.
  • Backtest methodology involved replicating first $20 purchase at specific price range.
  • Past performance unreliable predictor of future results for individual wallets.

QuickBooks Doesn't Speak EDI: How SMBs Bridge the X12 Gap

Your accounting system and your biggest customer are not arguing. They are simply speaking different languages, and neither one is going to learn the other's.

  • QuickBooks lacks EDI communication in X12 format
  • Translation layer bridges language barrier between QuickBooks and trading partners
  • Certification focuses on translation layer, not ERP system

More from Saturday 10 October →