Non-Production Endpoints as an Attack Surface in AWS

The security team at Datadog recently disclosed a security issue on AWS where non-production endpoints were used as an attack surface to silently perform permission enumeration. AWS has since remediated these specific bypasses.

Source: InfoQ

 


Date:

Categorie(s):