Cloud account hacks likely with AWS Security Token Service exploitation

Cloud accounts could be compromised to facilitate further malicious activity through the exploitation of the Amazon Web Services Security Token Service, according to The Hacker News. After using AWS STS to spoof cloud user identities, attackers could leverage API calls to identify roles and privileges associated with long-term IAM tokens, or AKIAs, exfiltrated through malware and phishing attacks, a Red Canary report showed.

Source: SC Magazine

 


Date:

Categorie(s):