
Vulnerabilities in AWS, GCP and Azure - Cloud Security News
Quenn D
Description
<p><strong>Cloud Security News this week - 22 September 2021</strong></p> <ul> <li>AWS, Google Cloud and Azure have all been busy last few weeks fixing and patching Vulnerabilities. In addition to Azure's OMIGOD flaws which we covered in last week’s episode,<a href="https://cloud.google.com/support/bulletins#gcp-2021-020"><u> Google Cloud reported that some of their load balancers were routing to an Identity-Aware Proxy (IAP) enabled Backend Service which could have been vulnerable to an untrusted party. Google Cloud have confirmed that this issue has been resolved.</u></a></li> <li><a href="https://rhinosecuritylabs.com/aws/cve-2021-38112-aws-workspaces-rce/"><u>Rhino Security Labs have discovered a vulnerability in AWS WorkSpaces, amazon’s virtual desktop. Exploiting this vulnerability allows commands to be executed if a victim opens a malicious WorkSpaces URI from their browser. Rhino reported the vulnerability to Amazon and it was promptly patched.</u></a></li> <li><a href="https://www.darkreading.com/attacks-breaches/mirai-botnet-exploiting-omigod-azure-vulnerability"><u>Attackers have begun to exploit critical Microsoft Azure vulnerabilities that were reported in last week’s episode. The OMIGOD flaws, discovered by the Wiz Research Team have since been patched by microsoft. New data indicates that attackers are scanning the Web for Azure Linux virtual machines that are vulnerable. If successful, an attacker could become root on a remote machine.</u></a></li> <li><a href="https://www.darkreading.com/cloud/How-attackers-invest-in-cloud-focused-cybercrime"><u>For organisations and enterprises cloud is about improved flexibility, scalability, and cost-effectiveness. For cybercriminals, Cloud is an environment filled with poorly secured enterprise data, applications, and online assets. IBM in their recently released Security X-Force Cloud Threat Landscape Report highlight increased attacker interest in the thriving black market for stolen credentials used to access enterprise accounts and resources on
Uploader
Episodes
Vulnerabilities in AWS, GCP and Azure - Cloud Security News
Quenn D