Observed arrival · 2026-08-30
Osprey: Three Cloud Risks That Chain Into One Incident
A local security scanner that connects cloud misconfigurations, identity reach, network exposure, and vulnerabilities into exploitable attack paths.
Field notes
The scanner reads AWS configuration through existing credentials or a generated read-only role, then represents principals, policies, resources, trust relationships, and exposure as one property graph. Its first-pass report foregrounds connected escalation paths rather than the full inventory, with each path showing the grant, route, and finding that triggered it. The page states that 25 deterministic rules are included and that cloud metadata remains local; an optional model receives only a pseudonymized digest.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue