๐จ BREAKING: Wiz Research discovers a massive 38TB data leak by Microsoft AI researchers, including 30,000+ internal Teams messages.
Here's what you need to know ๐งต
๐ What happened?
While releasing open-source training datasets, Microsoft's AI research team accidentally left the vault door open ๐
Over 38TB of data (!), including personal backups of employee workstations, private keys, and internal Microsoft Teams messages, were exposed.
Jul 11, 2023 โข 7 tweets โข 2 min read
๐จ BREAKING: History written with just 9 lines of code!
We've discovered #PyLoose, the FIRST documented Python-based fileless attack targeting cloud workloads.
See the power of 9 lines of Python code below ๐๐ฝ
Fileless attacks are known but rarely seen in the wild. The last reported instance in cloud workloads was 2.5 years ago ๐
Despite their rarity, fileless attacks pose significant threats due to their elusive nature and difficulty in detection.
Mar 10, 2023 โข 5 tweets โข 3 min read
3 cloud-to-K8s best practices to mitigate the risk of a lateral movement attack ๐ก
1๏ธโฃ Avoid storing long-term #cloud keys in workloads
2๏ธโฃ Remove kubeconfig files from publicly exposed workloads
3๏ธโฃ Restrict access to container registries
Details in thread ๐งต๐ #kubernetes
1๏ธโฃ Avoid storing long-term #cloud keys in workloads
โ Attach IAM roles/service accounts/managed identities to workloads and define minimum permissions.
โ Generate and rotate temporary credentials using the IMDS for improved #cloudsecurity.
๐งต 2/5
Feb 19, 2023 โข 6 tweets โข 4 min read
State of the #Cloud 2023: An in-depth report on the latest trends and risks โ
Report highlights in thread ๐งต or download the full report for free here ๐ wiz.io/blog/the-top-cโฆ
โ๏ธ The responsibility of #security professionals to stay up-to-date on the state of the #cloud has never been greater.
๐ก With cloud adoption continuing to grow, it is crucial to proactively address potential threats and ensure secure deployment of solutions.
๐งต2/6
Feb 17, 2023 โข 5 tweets โข 7 min read
Are you taking advantage of Rego's policy language for your #cloudsecurity needs?
If you're not, you need to check out these amazing resources to help get you started ๐งต๐