š£ Issue 84 is out. Highlights:
- Amazon Inspector enhances the security engine for container images scanning.
- AWS CloudTrail network activity events for VPC endpoints now generally available.
- whoAMI: A cloud image name confusion attack by Seth Art.
- Uncovering a Hidden CloudTrail Bug by Tracing AWS AssumeRole Chains in a Graph Database by Or Aspir.
- Tool: Cloud Trail Discover cheat sheet.
aws-cloudsec.com/p/issue-84
whoAMI research by DataDog. I immediately thought about all the user-data scripts that me be attached to those launched EC2 instance images š„¶
Kudos to @sethsec for the discovery, research, and tool!
#aws#cloudsecuritysecuritylabs.datadoghq.com/aā¦
Excellent research here from @sethsec and crew - including responsible disclosure, AWS hardening enhancement, detection guidance, etc.
š¤ I did report a name confusion in SSM Documents impacting Datadog right before this was found... š
Need to hack thousands of AWS customers? What about on internal AWS systems? Datadog Security Research found that a number of tools, including one published by AWS, are susceptible to name confusion attacks, leading to RCE in vulnerable environments!
securitylabs.datadoghq.com/aā¦
My Datadog Security Labs research is finally live! The whoAMI research highlights how a malicious actor could gain remote code execution in thousands of AWS accounts that are vulnerable to this attack.
securitylabs.datadoghq.com/aā¦
šIn this article we talk about how I exploited a Fortune 500 Through Hidden Supply Chain Links
Link š
landh.tech/blog/20241028-hidā¦
Thanks to the entire @HashiCorp team ! š¤
Enjoy š„
āļø State of Cloud Security
2024 update of @Datadogās report analyzing security posture data from a sample of thousands of orgs across AWS, Azure, and Google Cloud
⢠Long-lived credentials continue to be a major risk.
⢠Adoption of public access blocks in cloud storage services is rapidly increasing,
⢠<1/2 of EC2 instances enforce IMDSv2, but adoption is growing
⢠Securing managed Kubernetes clusters requires non-default, cloud-specific tuning
⢠Insecure IAM roles for third-party integrations leave AWS accounts at risk of exposure
⢠Most cloud incidents are caused by compromised cloud credentials
datadoghq.com/state-of-cloudā¦
Excited to share some research I've been working on for the past few months, based on real-world data from thousands of environments using AWS, Azure and Google Cloud!
datadoghq.com/state-of-cloudā¦
I had such a great time speaking about Cloud Security at @BsidesORL! I saw some great talks, made some new friends, and got to hang with old ones. A huge thank you to all of the volunteers that made this epic event possible!
This is a killer talk! If you have not seen it yet, make some time to watch Nick explain some really cool initial access techniques he found in a super approachable way!
My talk at DEF CON 32 is now on YouTube! "Kicking in the Door to the Cloud: Exploiting Cloud Provider Vulnerabilities for Initial Access" is a look at vulnerabilities I've found in AWS services that provided initial access to victim environments!
youtube.com/watch?v=oAriLYN-ā¦
Great blog post from @permisosecurity on LLMHijacking attacks against AWS Bedrock. I remember when we first started seeing this behavior from threat actors and I couldn't figure out why they would target Bedrock. Well, I guess we have on answer. š§µ
permiso.io/blog/exploiting-hā¦