Attack Paths Into VMs in the Cloud
ID: 1d483319-80dc-56a9-bdce-684ad0f3f898
STIX ID: report--1d483319-80dc-56a9-bdce-684ad0f3f898
Feed Name: Palo Alto Networks Unit 42
This report surveys common attack paths for cloud VM services across AWS, Azure, and GCP—such as vulnerability exploitation, startup script manipulation, SSH key insertion, direct code execution via management agents, session-based access (e.g., AWS SSM), and serial console access—and explains required preconditions, key permissions, and mitigations for each. It stresses that these are legitimate platform features that can be abused if IAM, configuration, and operational controls are weak, and provides concrete guidance to restrict risky permissions, harden agents and metadata usage, and disable unneeded access mechanisms to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
