Cloud misconfiguration has evolved and your controls haven’t
ID: ee2a3aed-039f-5bcd-bf2a-40d243ac9b12
STIX ID: report--ee2a3aed-039f-5bcd-bf2a-40d243ac9b12
Feed Name: Help Net Security
Threat Score
The report outlines two AWS misconfigurations that can be abused by attackers: bucket name squatting (registering expected S3 bucket names to receive misrouted data or code) and a cross-service confused-deputy issue (resource policies that trust AWS services without restricting the source account). It recommends fixes including tying bucket names to account IDs and regions and adding condition keys to resource policies to lock trust to specific accounts or organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
