This week's articles
When MFA isn't actually MFA
#attack, #saas
Retool experienced a security breach due to a spear phishing attack in August 2023. Attackers used social engineering tactics, compromising an employee's Google Authenticator, which exposed multi-factor authentication (MFA) codes.
Security flaws in an SSO plugin for Caddy
#attack
The Trail of Bits team identified 10 security vulnerabilities within the caddy-security plugin for the Caddy web server that could enable a variety of high-severity attacks in web applications, including client-side code execution, OAuth replay attacks, and unauthorized access to resources.
Ransomware Strikes Azure Storage: Are You Ready?
#attack, #azure, #defend
Post discussing Azure Storage Accounts, pointing out forensic artifacts in Azure that can help investigate ransomware attacks, and offering methods for attack detection.
Maintaining persistence via Shared sessions on Cloud Workstations
#attack, #gcp
When an owner initiates a session and performs actions like gcloud auth login, the session state persists, shared across multiple users accessing the workstation through the same URL. This means that any user with access to the workstation can view and interact with the session artifacts created by the owner.
|
|
Tools
iamlive
Iamlive, which generates least privilege roles by intercepting network calls to your cloud environment, now supports also Azure and GCP.
cap
A collection of authentication Go packages related to OIDC, JWKs, Distributed Claims, LDAP.
dockle
Container image linter for security.
pmv
PMV is a tiny utility for working with the 1password CLI.
|
|
Sponsor
CNAPP for Dummies Wiz partnered with Wiley to create the Cloud Native Application Protection Platform (CNAPP) for Dummies eBook. This free 48-page PDF includes everything you *need* to know to secure the changing landscape of cloud-native applications and protect your cloud environment today. You’ll learn:- The fundamentals of cloud-native security
- Powerful tactics to strengthen security measures
- Best practices for getting started
- Techniques to shift security up the pipeline (and ahead of threats)
- 10 strategies for maximizing the potential of your CNAPP
Get your free guide here.
|
|
|
Jobs
Hiring? Feature your listings below - reach out now at [email protected]
|
|
|
Senior Cloud Security Engineer - Snowflake
Snowflake is looking for experts in cloud security architecture and operations who can help them maintain highly defensible cloud infrastructure, and follow SecDevOps best practices to reduce toil for their team and their internal customers.
|
|
Thanks for reading!
|
If you found this newsletter helpful, I'd really appreciate if you could forward it to your friends and colleagues! 👌 If you have questions, comments, or feedback, let me know on Twitter ( @lancinimarco / @CloudSecList), or at feedback.cloudseclist.com! Thanks, Marco
|
|
|