Cloud Security Research and Advocacy @Datadoghq. Previous: Cloud Penetration Testing lead @BishopFox. Also on Mastodon infosec.exchange/@sethsec

Joined June 2010
30 Photos and videos
Seth Art retweeted
šŸ“£ Issue 84 is out. Highlights: - Amazon Inspector enhances the security engine for container images scanning. - AWS CloudTrail network activity events for VPC endpoints now generally available. - whoAMI: A cloud image name confusion attack by Seth Art. - Uncovering a Hidden CloudTrail Bug by Tracing AWS AssumeRole Chains in a Graph Database by Or Aspir. - Tool: Cloud Trail Discover cheat sheet. aws-cloudsec.com/p/issue-84

2
8
436
Seth Art retweeted
whoAMI research by DataDog. I immediately thought about all the user-data scripts that me be attached to those launched EC2 instance images 🄶 Kudos to @sethsec for the discovery, research, and tool! #aws #cloudsecurity securitylabs.datadoghq.com/a…

1
1
8
397
Seth Art retweeted
Excellent research here from @sethsec and crew - including responsible disclosure, AWS hardening enhancement, detection guidance, etc. šŸ¤” I did report a name confusion in SSM Documents impacting Datadog right before this was found... 😜
Need to hack thousands of AWS customers? What about on internal AWS systems? Datadog Security Research found that a number of tools, including one published by AWS, are susceptible to name confusion attacks, leading to RCE in vulnerable environments! securitylabs.datadoghq.com/a…
2
1
13
844
14 Feb 2025
My Datadog Security Labs research is finally live! The whoAMI research highlights how a malicious actor could gain remote code execution in thousands of AWS accounts that are vulnerable to this attack. securitylabs.datadoghq.com/a…

1
4
18
802
14 Feb 2025
The post also includes many ways you can check to see if you are vulnerable!
63
Seth Art retweeted
1 Nov 2024
What. The.
138
999
6,588
1,367,814
Seth Art retweeted
28 Oct 2024
šŸ”—In this article we talk about how I exploited a Fortune 500 Through Hidden Supply Chain Links Link šŸ‘‡ landh.tech/blog/20241028-hid… Thanks to the entire @HashiCorp team ! 🤟 Enjoy šŸ”„
9
77
301
23,818
Seth Art retweeted
ā˜ļø State of Cloud Security 2024 update of @Datadog’s report analyzing security posture data from a sample of thousands of orgs across AWS, Azure, and Google Cloud • Long-lived credentials continue to be a major risk. • Adoption of public access blocks in cloud storage services is rapidly increasing, • <1/2 of EC2 instances enforce IMDSv2, but adoption is growing • Securing managed Kubernetes clusters requires non-default, cloud-specific tuning • Insecure IAM roles for third-party integrations leave AWS accounts at risk of exposure • Most cloud incidents are caused by compromised cloud credentials datadoghq.com/state-of-cloud…
1
15
38
3,711
Seth Art retweeted
Mine & @sabi_elezi's #MaLDAPtive presentation from @defcon is now posted on YouTube! LDAP obfuscation, deobfuscation & detection - all built on our 100% custom LDAP parser. Recording: youtube.com/watch?v=mKRS5Iyy… Tool: github.com/MaLDAPtive/Invoke… @permisosecurity #LDAP #ClippyGotJokes
1
35
94
6,345
Seth Art retweeted
Excited to share some research I've been working on for the past few months, based on real-world data from thousands of environments using AWS, Azure and Google Cloud! datadoghq.com/state-of-cloud…
1
32
78
4,414
Seth Art retweeted
How it feels to be on the other side… #Bluesky
2
5
1,105
20 Oct 2024
I had such a great time speaking about Cloud Security at @BsidesORL! I saw some great talks, made some new friends, and got to hang with old ones. A huge thank you to all of the volunteers that made this epic event possible!
10
337
17 Oct 2024
This is a killer talk! If you have not seen it yet, make some time to watch Nick explain some really cool initial access techniques he found in a super approachable way!
My talk at DEF CON 32 is now on YouTube! "Kicking in the Door to the Cloud: Exploiting Cloud Provider Vulnerabilities for Initial Access" is a look at vulnerabilities I've found in AWS services that provided initial access to victim environments! youtube.com/watch?v=oAriLYN-…
1
3
383
Seth Art retweeted
Great blog post from @permisosecurity on LLMHijacking attacks against AWS Bedrock. I remember when we first started seeing this behavior from threat actors and I couldn't figure out why they would target Bedrock. Well, I guess we have on answer. 🧵 permiso.io/blog/exploiting-h…
2
12
45
6,847
4 Oct 2024
Really looking forward to speaking at BSides Orlando in two weeks!
Join Seth Art @sethsec for "Six degrees of (cloud) escalation" at BSides ORL - Oct 19th!
2
12
1,187