JSTGTECH
← All posts

Tagged “cloud”

3 posts

The Capital One breach: an SSRF bug into 100M records

A misconfigured WAF and an SSRF bug let an attacker reach the AWS metadata service and steal role credentials — exposing 100M+ Capital One records.

securityawsiamcloud

Exposed Kubernetes API Servers Are an RBAC Time Bomb

Attackers are actively hunting internet-facing Kubernetes API servers with anonymous-auth on and default service accounts holding broad RBAC access.

securitykubernetesrbaccloud

The 198M-voter S3 leak that still explains most breaches

A 2017 misconfigured S3 bucket exposed 198 million voter records, and the same public-bucket misconfiguration still causes new breaches every year.

securityawss3cloud