New Bucket Hijacking Attack Allows Hackers to Reroute Cloud Data Streams to External Storage
ID: 3e680027-a119-510b-998f-e0b8228405c9
STIX ID: report--3e680027-a119-510b-998f-e0b8228405c9
Feed Name: cybersecurityNews.com
Unit 42 describes a critical "bucket hijacking" technique that leverages globally-unique cloud storage names: an attacker who can delete a victim's storage bucket can recreate the same-named bucket under their control, causing logging sinks, replication, and telemetry to be silently redirected into attacker-owned buckets across Google Cloud, AWS, and Azure; the attack is stealthy because sinks continue to report as valid, and recommended defenses include restricting deletion permissions, enforcing perimeter controls (SCPs/VPC Service Controls), enabling account-scoped namespaces, and alerting on bucket deletion API calls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
