Hacking the Cloud
@hackingthcloud
The official Twitter account for Hacking the Cloud, the open-source encyclopedia of offensive security techniques in the cloud. Created by @frichette_n
ID: 1754918175991267328
https://hackingthe.cloud/ 06-02-2024 17:21:54
89 Tweet
210 Followers
1 Following
šØ New on Hacking the Cloud: Discover how misconfigured tagBindings.create permissions in GCP can lead to privilege escalation. Learn how attackers can exploit tags to gain elevated access. Stay informed and secure your cloud infrastructure. Read more: hackingthe.cloud/gcp/exploitatiā¦
Want to learn more about Administrative Unit attack paths in Azure? Check out Katie Knowles's talk about it from SpecterOps Con! youtube.com/watch?v=oxD7-Uā¦
š¾ It's up!! Everything you ever wanted to know about Entra Administrative Unit attack paths, from my talk at SpecterOps SO-CON: youtube.com/watch?v=oxD7-Uā¦
New on Hacking the Cloud! Tired of well-known enumeration strategies that could get you caught? Why not think outside the box? This article covers enumeration of resources using the AWS Backup service. I have related research on this topic coming soon! hackingthe.cloud/aws/enumeratioā¦
𤩠I just came across this fascinating talk by Nick Frichette at fwd:cloudsec: āHidden Among the Cloud: A Look at Undocumented AWS APIs.ā youtube.com/watch?v=f7AuDxā¦
Safe travels to everyone coming to fwd:cloudsec! Itās the densest concentration of cloud security nerds in the world!
Itās a month and a half away but Iām already super excited for fwd:cloudsec EU! If youāll be there in Berlin, come find me for limited edition, holographic, Hacking the Cloud stickers!
Cloud attackers keep evolving. So should defenses. Enumeration through AWS Resource Explorer used to be invisible. Not anymore. Breakdown from Datadog, Inc.: securitylabs.datadoghq.com/articles/enumeā¦
Great write up from the Cyber Security News on our latest open-source tool, #Inboxfuscation, in their newsletter today. "A new open-source tool named Inboxfuscation can create malicious inbox rules in Microsoft Exchange that are difficult for security tools to detect. Developed by
New on Hacking the Cloud! A great post by Federico Lucini on bypassing AWS Network Firewall egress filtering! hackingthe.cloud/aws/post_exploā¦
After years of hacking on Azure it feels great to finally get 1st š„ Thanks Microsoft Security Response Center ā¤ļø