logo

'Damn Vulnerable' Training Apps Leave Vendors' Clouds Exposed

ID: 2d2413f9-b2ae-56ed-9973-03200e0fefbd

STIX ID: report--2d2413f9-b2ae-56ed-9973-03200e0fefbd

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

Pentera researcher Noam Yaffe found thousands of deliberately vulnerable training web applications exposed on the public internet; 1,926 were accessible and 974 ran on major cloud providers. At least 165 had IAM roles attached (109 over‑permissioned), enabling RCE chains that accessed cloud metadata and temporary credentials — in some cases yielding AdministratorAccess and full cloud compromise. Artifacts show active abusive use (e.g., XMRig cryptomining) and multiple major security vendors were affected, highlighting a systemic risk from insecure training apps in production environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.