Black Hat 2021: How isolated is your AWS cloud environment?
ID: 6c4b90f2-621c-5f3f-9404-c3e304144415
STIX ID: report--6c4b90f2-621c-5f3f-9404-c3e304144415
Feed Name: Wiz Blog
Wiz researchers disclosed a new class of AWS cross-account vulnerabilities in CloudTrail, AWS Config, and Serverless Repository that could let an attacker cause AWS services to perform actions on the attacker’s behalf, enabling unauthorized read/write access into other customers’ accounts (including private S3 buckets). AWS added policy conditions to mitigate the issue, but because customers must update their resource policies, Wiz’s survey found many environments remain vulnerable—Wiz warns this exposure could permit data exfiltration and that similar issues may exist in other AWS services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
