Cloud Security
Cloud Ransomware: Soft-Delete and Versioning Are the Whole Story
One over-permissioned Service Principal leaked through an old configuration, and we could read, delete, replace and encrypt every blob. The difference between 'restored in five minutes' and 'we…
Read itCloud Security
Attackers Are Running Their C2 on Your Cloud, and You Are Paying for It
No fixed IP to block. No suspicious infrastructure for the SIEM to catch. The traffic belongs to Amazon and the invoice arrives at the end of the month…
Read itCloud Security
A Quarter of Azure Identities Trusting GitHub Actions Are Takeable. Right Now.
When a repo is deleted or a namespace freed, the OIDC trust policy stays. Anyone can re-register that namespace, get a valid token, and walk into your cloud…
Read itCloud Security
An Hour Into the Assessment We’re Cloud Admin – and It’s Never a Zero-Day
Most companies believe their cloud is secure because someone configured IAM policies and the CSPM shows green. We get admin inside an hour, from an IAM policy copied…
Read itCloud Security
One Cyrillic Letter, and the Identity Provider Was Theirs
Cognito checks that Identity Provider names are unique - at the byte level, not the visual one. U+0435 looks exactly like a Latin e, and the system accepted…
Read itCloud Security
Attackers Don’t Break Into Your Cloud. They Log In.
No exploit, no zero-day, nothing that trips an alert. A Cognito refresh token can be valid for ten years, and CloudTrail sees everything while understanding nothing.
Read itCloud Security
There Is No Safe Starter Kit. There Is Only One Nobody Has Tested Yet.
A starter kit that generates IAM roles with wildcard permissions on every resource. AWS's fix was to update the documentation.
Read itCloud Security
Still Using SSRF to Take Over Cloud Deployments Once Again
How Server-Side Request Forgery Can Lead to Full Cloud Compromise - and What You Can Do About It Contents Introduction Server-Side Request Forgery (SSRF) is a powerful exploit…
Read itCloud Security
Firestore White Box Security Review Checklist
Table of Contents Introduction Securing your application’s Firestore database is crucial for protecting sensitive data and maintaining user trust. Google Firestore, a scalable NoSQL cloud database, offers robust…
Read itCloud Security
Firebase Applications – The Untold Attack Surface
Introduction In this blogpost, we will review some of the basic components of a Firebase application from a Security Perspective and talk about common issues that don’t get…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.