Cloud security explained: What’s left exposed?
ID: e9b9d83e-05a1-554d-b0a8-79a518d43bea
STIX ID: report--e9b9d83e-05a1-554d-b0a8-79a518d43bea
Feed Name: The Register (Security)
Date Published: 2025-03-31
Date Updated: 2026-04-26
Author: Daniel Andrew, Head of Security Services, Intruder
The article clarifies AWS’s Shared Responsibility Model, emphasizing that customers must secure application, identity, OS, network, and configuration layers, with examples like SSRF to the metadata service, public S3 bucket misconfigurations, IDOR risks in SaaS apps, and the need for patch management and proper network exposure; it recommends defenses such as fixing SSRF, enabling IMDSv2, enforcing least privilege and secure access patterns, and keeping runtimes up to date, and concludes by promoting Intruder’s agentless cloud security scanning to detect misconfigurations, vulnerabilities, and exposed services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
