Viewing profile — daudmalik06
daudmalik06
HN member- Joined
- Sat, Nov 13, 2021, 1:53 PM UTC
- HN karma
- 15
- Public activity
- 69 items
- HN profile
- View on Hacker News ↗
About daudmalik06
GCP has no native kill switch for compromised API keys. Budget alerts lag 4-12 hours. By the time they fire, the damage is already done.
CloudSentinel polls raw request counts via GCP Cloud Monitoring every minute and revokes the key automatically when a threshold is crossed. No human in the loop. Confirmed working in production.
cloudsentinel.dev — 14-day free trial, no credit card.
Recent public activity
-
comment
Comment #49067594
I’ve been comparing several software composition analysis tools, including Vulert, to understand how differently they identify and prioritize vulnerable dependencies. Most SCA prod…
- story
- story
- story
- story
-
comment
Comment #47591856
does it support php codebase ? specifically laravel ?
-
story
Ask HN: Is there any founder building non AI startup in 2026?
Ask HN: Is there any founder building non AI startup in 2026 ? Just curious to know what other founders are building around and what are current challenges.
-
comment
Comment #47591791
interesting, a question will it download the code ? how does it work technically ?
- story
- story
-
comment
Comment #47494889
[dead]
-
comment
Comment #47494886
The approaches make sense for teams with engineering resources to build internal tooling. The LLM gateway layer is smart — virtual keys with caps is exactly the right mental model.…
-
story
Tell HN: A company was billed $128K from one leaked GCP API key
I've been collecting real incidents over the past few months. The pattern is always identical: - $128,000 — small company in Japan, caught it at $44K, shut everything down, charges…
-
comment
Comment #47322721
Original incident: https://www.reddit.com/r/googlecloud/s/3S1KWpWRZm After reading about a 3-person startup that received an $82,000 Gemini API bill in 48 hours (normal monthly spe…
- story
- story
- story
-
story
Show HN: Open-Source Security Monitoring with AI and License Compliance
Hey Hacker News, I’m Dawood, creator of Vulert. We’ve just released Vulert 2.0, a platform designed to monitor open-source dependencies for security vulnerabilities, ensure license…
-
story
Attention: RCE Vulnerability Discovered in Laravel
Attention Laravel developers: The Laravel RCE vulnerability in the "cookie" session driver exposes the encryption keys, allowing attackers to execute remote code on affected system…
-
comment
Comment #39144639
really thanks for kind suggestions, it really means a lot. i will save your comment and will try to test and validate what you suggested. thanks again mate.
-
story
Ask HN: We're tired and need your support
Dear Folks, It's been a challenging journey, nearly two years of relentless effort, and yet our startup has faced its fair share of setbacks. We've chosen to bootstrap our venture …
-
story
Show HN: Compliant SBOM Management per US Senate Directive
Excited to introduce Vulert to the HackerNews community! As many are aware, the US government now mandates vendors to provide SBOMs (Software Bill of Materials) - essentially detai…
-
story
Show HN: Investment opportunity in a cyber security startup
Hey Folks, After months of hard work and dedication, we're thrilled to announce that #Vulert is taking a bold step forward. As we continue our mission to redefine the landscape of …
-
comment
Comment #37958281
not a bad deal, perhaps :D
-
comment
Comment #37957999
you can also reach out to me at ceo@vulert.com