Focal Security 리트윗함

I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. 🪣
In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP.
Here is how it works:

English
