Hidden Dangers in the Cloud Control Plane
ID: b562664b-3bc4-5972-84e7-41c21648bb5c
STIX ID: report--b562664b-3bc4-5972-84e7-41c21648bb5c
Feed Name: Mitiga
Threat Score
This Mitiga research report shows how GCP Compute APIs (notably getSerialPortOutput and setMetadata) can be abused to establish stealthy command-and-control and data exfiltration channels to VMs even when those VMs are firewalled; it describes attacker scenarios requiring cloud credential or permission compromise, documents disclosure to Google, and provides hardening and hunting guidance to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
