Security News

Cybersecurity news aggregator

☁️
MEDIUM Vulnerabilities Help Net Security

Cloud misconfiguration has evolved and your controls haven’t

  • What: New AWS misconfiguration techniques like bucket name squatting are identified
  • Impact: Cloud users need to review their S3 configurations
Read Full Article →

In this Help Net Security video, Kat Traxler, Principal Security Researcher – Public Cloud at Vectra AI, walks through two AWS misconfigurations that go beyond the basics of bucket visibility. The first is bucket name squatting. Because S3 uses a global namespace, attackers can register bucket names they expect a target company will use, then wait for data or code to route their way. AWS recently addressed this by tying bucket names to account IDs … More → The post Cloud misconfiguration has evolved and your controls haven’t appeared first on Help Net Security .

Share this article