Tagged “cloud”
3 posts
The Capital One breach: an SSRF bug into 100M records
A misconfigured WAF and an SSRF bug let an attacker reach the AWS metadata service and steal role credentials — exposing 100M+ Capital One records.
securityawsiamcloud
Exposed Kubernetes API Servers Are an RBAC Time Bomb
Attackers are actively hunting internet-facing Kubernetes API servers with anonymous-auth on and default service accounts holding broad RBAC access.
securitykubernetesrbaccloud
The 198M-voter S3 leak that still explains most breaches
A 2017 misconfigured S3 bucket exposed 198 million voter records, and the same public-bucket misconfiguration still causes new breaches every year.
securityawss3cloud