logo

Attack Paths Into VMs in the Cloud

ID: 1d483319-80dc-56a9-bdce-684ad0f3f898

STIX ID: report--1d483319-80dc-56a9-bdce-684ad0f3f898

Feed Name: Palo Alto Networks Unit 42

Date Published: 2024-06-18

Date Updated: 2026-04-28

Author: Jay Chen

...
...

This report surveys common attack paths for cloud VM services across AWS, Azure, and GCP—such as vulnerability exploitation, startup script manipulation, SSH key insertion, direct code execution via management agents, session-based access (e.g., AWS SSM), and serial console access—and explains required preconditions, key permissions, and mitigations for each. It stresses that these are legitimate platform features that can be abused if IAM, configuration, and operational controls are weak, and provides concrete guidance to restrict risky permissions, harden agents and metadata usage, and disable unneeded access mechanisms to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.