Scott Piper

@scottpiper.bsky.social

Cloud security historian. Developed http://flaws.cloud, CloudMapper, and Parliament. Founding team for fwdcloudsec.org Principal Cloud Security Researcher at Wiz.

A lot of cloud service providers beyond AWS allow you to store data in something that looks and acts like S3, but there are differences worth investigating. Check out my latest article discussing the security risks that carry over and the assumptions that break. www.wiz.io/blog/s3-clon...

S3 Clones in the Neoclouds | Wiz Blog

S3 compatible services carry many of the same concerns as the original S3 service. This article highlights which assumptions break and what risks remain.

wiz.io

"Funny and distressingly realistic...propelled by awesome characters and inventive twists” — Andy Weir Silicon Valley invents the time machine in my upcoming book PARADOX INC, now available for preorder everywhere! Here's a look inside from @people.com: people.com/paradox-inc-...

Former Google Employee Announces Silicon Valley Satire, ‘Paradox Inc.’ — See the Cover! (Exclusive)

Forrest Brazael, a former Google employee, chronicles the fall and rise of a time-travel startup in his forthcoming book, ‘Paradox Inc.’

people.com

The CFP for fwd:cloudsec North America closes this Friday (March 20) at midnight Pacific time! Hotel and travel costs are taken care of for speakers (some caveats apply), plus tickets. Come speak June 1&2 near Seattle. fwdcloudsec.org/conference/n...

CFP | NA 2026 | fwd:cloudsec

fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...

fwdcloudsec.org

It pains me when I hear people say "I thought about submitting a talk to the fwd:cloudsec, but didn't because..." and the reasons are often things I actually want to see presentations on! Some talk ideas I personally want to watch (the other reviewers and I will fight ⚔️):

Tickets go on sale next week on Monday, Feb 9, at 10:00 a.m. PST for our North American conference happening near Seattle on June 1 and 2. An additional small batch will go on sale that evening at 11:00 p.m. PST. Tickets will be available for purchase here: www.eventbrite.com/e/fwdcloudse...

fwd:cloudsec North America 2026

fwd:cloudsec is the industry's leading independent, community-driven cloud security conference. All times listed are in US/Pacific time.

eventbrite.com

Did you know Claude models have a "magic string" to test when a model refuses to respond? If that string enters prompt context, it can be abused to break LLM workflows until context is reset. It's the EICAR test string of the AI age. Details: hackingthe.cloud/ai-llm/explo...

Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud

How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.

hackingthe.cloud

We've locked in dates and venues for the North American (NA) and European (EU) fwd:cloudsec conferences this year! fwd:cloudsec NA will be in the Seattle, Washington area at the Meydenbauer Center in Bellevue on June 1 and 2. 🧵

What are we calling normal AWS now? Normal, standard, classic, commercial, global, american? How do you say out loud the acronym for AWS European Sovereign Cloud? I'm calling it "oosk", because the region is eusc-de-east-1, which sounds like a riff on the techno onomatopoeia "boots and cats".

Very cool research on a CodeBuild misconfiguration which could have had significant consequences. I’m a bit disappointed that there wasn’t more done to secure the supply chain after the Q Developer incident. www.wiz.io/blog/wiz-res...

CodeBreach: Supply Chain Vuln & AWS CodeBuild Misconfig | Wiz Blog

Wiz Research discovered CodeBreach, a critical vulnerability that risked the AWS Console supply chain. Learn how to secure your AWS CodeBuild pipelines.

wiz.io

December is generally a good time for gifts, and I have a special one for you. We are glad to announce fwd:cloudsec Europe 2026: September 7th and 8th - London, UK 🇬🇧 More info to come early 2026. Stay tuned, folks.

It’s time to bust some malware! 🦠 Challenge #6 “Malware Busters” is LIVE. Built by Gili Tikochinski for the reverse‑engineering pros - dive into assembly and uncover what’s hidden inside. Think you can crack it? cloudsecuritychampionship.com/challenge/6

The Ultimate Cloud Security Championship | 12 Months × 12 Challenges

Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.

cloudsecuritychampionship.com

I feel like the biggest takeaway from the latest AWS outage is that there’s simply no architecting around them at this point. Even if you are 100% redundant/multi-whatever, your vendors and customers are certainly not. Order volume is dropping no matter what you do. We’re all in this together.