Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    Cloud Security

    • Home
    • Blog
    • Cloud Security
    Cloud Security

    Cloud Ransomware: Soft-Delete and Versioning Are the Whole Story

    July 7, 2026 No comments yet

    One over-permissioned Service Principal leaked through an old configuration, and we could read, delete, replace and encrypt every blob. The difference between ‘restored in five minutes’ and ‘we paid’ is two boring settings.

    Cloud Security

    An Hour Into the Assessment We’re Cloud Admin – and It’s Never a Zero-Day

    June 10, 2026 No comments yet

    Most companies believe their cloud is secure because someone configured IAM policies and the CSPM shows green. We get admin inside an hour, from an IAM policy copied off Stack Overflow two years ago.

    Cloud Security

    One Cyrillic Letter, and the Identity Provider Was Theirs

    May 21, 2026 No comments yet

    Cognito checks that Identity Provider names are unique – at the byte level, not the visual one. U+0435 looks exactly like a Latin e, and the system accepted both.

    Cloud Security

    Attackers Don’t Break Into Your Cloud. They Log In.

    May 16, 2026 No comments yet

    No exploit, no zero-day, nothing that trips an alert. A Cognito refresh token can be valid for ten years, and CloudTrail sees everything while understanding nothing.

    Cloud Security

    There Is No Safe Starter Kit. There Is Only One Nobody Has Tested Yet.

    May 7, 2026 No comments yet

    A starter kit that generates IAM roles with wildcard permissions on every resource. AWS’s fix was to update the documentation.

    Still Using SSRF to Take Over Cloud Deployments Once Again
    Cloud Security

    Still Using SSRF to Take Over Cloud Deployments Once Again

    January 16, 2025 Michael Yermakov No comments yet

    How Server-Side Request Forgery Can Lead to Full Cloud Compromise – and What You Can Do About It Introduction Server-Side Request Forgery (SSRF) is a powerful exploit that enables attackers to trick a vulnerable server into making arbitrary HTTP requests on their behalf. While some view SSRF as merely a method to force the server […]

    Cloud Security

    Firestore White Box Security Review Checklist

    February 7, 2023 Michael Yermakov No comments yet

    Introduction Securing your application’s Firestore database is crucial for protecting sensitive data and maintaining user trust. Google Firestore, a scalable NoSQL cloud database, offers robust features for real-time data management, but securing it against threats requires careful attention. This article is designed to help developers and security professionals assess and strengthen their Firestore implementations. A […]

    Cloud Security

    Firebase Applications – The Untold Attack Surface

    September 14, 2020 AppSec Labs No comments yet

    Introduction In this blogpost, we will review some of the basic components of a Firebase application from a Security Perspective and talk about common issues that don’t get enough attention. What is Firebase? Firebase is a complete backend as a service with many different features that we can plug straight into our applications. For example: There […]

    Search

    Categories

    • AI and LLM Security (26)
    • API Security (7)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (13)
    • Engagements and Process (10)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (15)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy