Top cloud threats that you never knew existed – and pragmatic steps to avoid them
Expanded cloud adoption brings new critical vulnerabilities – like OMIGOD, CloudDB and flawed multitenant isolation – as threat finders at Wiz Research have discovered.
Cloud adoption is expanding rapidly, and with that expansion comes new complexities. The speed of growth and change in the cloud creates an ever-changing threat landscape. Wiz Research is at the forefront of the cloud’s threat landscape and is behind the discovery of significant vulnerabilities such as ChaosDB, ExtraReplica, AttachMe, BingBang, and OMIGOD.
In this session, we will thoroughly examine the latest cloud threats identified by the Wiz Research team. This will include design gaps affecting cloud customers, the dangers of insecure tenant isolation, and the risks associated with silent agents. The information presented will summarise insights gathered from various research efforts , including Wiz research and general community research.
The Register’s James Hayes is joined by Shir Tamari, Head of Vulnerability Research at Cloud Security Specialist Wiz, to discuss the emerging trends in cloud vulnerabilities and the changing attack patterns for cloud-based resources. You will learn about:
Faulty cloud configurations introduces an additional attack vector that can compromise data security
Insights into the risks of silent agents that resulted in cloud vulnerabilities like OMIGOD
ChaosDB resulted from a trivial exploit in a remote account takeover of Azure's flagship database, impacting numerous F500 companies
Insecure tenant-isolation implementation resulted from a trivial exploit in a remote account takeover of Azure's flagship database, impacting numerous F500 companies
Pragmatic guidance and tools for dev, ops, and security teams to reduce the risk of these threats