Seth Art

1.1K posts

Seth Art banner
Seth Art

Seth Art

@sethsec

Cloud Security Research and Advocacy @Datadoghq. Previous: Cloud Penetration Testing lead @BishopFox. Also on Mastodon https://t.co/R1KYbwIdme

Ithaca, NY Katılım Haziran 2010
370 Takip Edilen1.4K Takipçiler
Seth Art retweetledi
AWS Cloud Security Weekly
AWS Cloud Security Weekly@awscloudsec·
📣 Issue 84 is out. Highlights: - Amazon Inspector enhances the security engine for container images scanning. - AWS CloudTrail network activity events for VPC endpoints now generally available. - whoAMI: A cloud image name confusion attack by Seth Art. - Uncovering a Hidden CloudTrail Bug by Tracing AWS AssumeRole Chains in a Graph Database by Or Aspir. - Tool: Cloud Trail Discover cheat sheet. aws-cloudsec.com/p/issue-84
English
0
2
8
408
Seth Art retweetledi
Rami McCarthy
Rami McCarthy@ramimacisabird·
Excellent research here from @sethsec and crew - including responsible disclosure, AWS hardening enhancement, detection guidance, etc. 🤔 I did report a name confusion in SSM Documents impacting Datadog right before this was found... 😜
Nick Frichette@Frichette_n

Need to hack thousands of AWS customers? What about on internal AWS systems? Datadog Security Research found that a number of tools, including one published by AWS, are susceptible to name confusion attacks, leading to RCE in vulnerable environments! securitylabs.datadoghq.com/articles/whoam…

English
2
1
14
826
Seth Art
Seth Art@sethsec·
The post also includes many ways you can check to see if you are vulnerable!
English
0
0
0
60
Seth Art
Seth Art@sethsec·
My Datadog Security Labs research is finally live! The whoAMI research highlights how a malicious actor could gain remote code execution in thousands of AWS accounts that are vulnerable to this attack. securitylabs.datadoghq.com/articles/whoam…
English
1
4
18
796
Seth Art
Seth Art@sethsec·
@_xDeJesus Thanks for sharing @_xDeJesus. Spot on about the user-data. And just think about all of the attached IAM roles and permissions as well!
English
0
0
1
25
Seth Art retweetledi
Matt Johansen
Matt Johansen@mattjay·
What. The.
Matt Johansen tweet media
English
138
1K
6.6K
1.4M
Seth Art retweetledi
Lupin
Lupin@0xLupin·
🔗In this article we talk about how I exploited a Fortune 500 Through Hidden Supply Chain Links Link 👇 landh.tech/blog/20241028-… Thanks to the entire @HashiCorp team ! 🤟 Enjoy 🔥
Lupin tweet media
English
9
78
303
23.7K
Seth Art retweetledi
Clint Gibler
Clint Gibler@clintgibler·
☁️ State of Cloud Security 2024 update of @Datadog’s report analyzing security posture data from a sample of thousands of orgs across AWS, Azure, and Google Cloud • Long-lived credentials continue to be a major risk. • Adoption of public access blocks in cloud storage services is rapidly increasing, • <1/2 of EC2 instances enforce IMDSv2, but adoption is growing • Securing managed Kubernetes clusters requires non-default, cloud-specific tuning • Insecure IAM roles for third-party integrations leave AWS accounts at risk of exposure • Most cloud incidents are caused by compromised cloud credentials datadoghq.com/state-of-cloud…
English
1
15
38
3.7K
Seth Art retweetledi
Christophe Tafani-Dereeper
Christophe Tafani-Dereeper@christophetd·
Excited to share some research I've been working on for the past few months, based on real-world data from thousands of environments using AWS, Azure and Google Cloud! datadoghq.com/state-of-cloud…
English
1
32
79
4.4K
Seth Art
Seth Art@sethsec·
I had such a great time speaking about Cloud Security at @BsidesORL! I saw some great talks, made some new friends, and got to hang with old ones. A huge thank you to all of the volunteers that made this epic event possible!
Seth Art tweet mediaSeth Art tweet mediaSeth Art tweet media
English
0
0
10
333