Suivre

silently install management agents on VMs, which now have RCE & LPE vulnerabilities ! « OMI is just one example of a secret agent that's pre-installed and silently deployed in cloud environments » ; « Thanks to the combination of a simple conditional statement coding mistake and an uninitialized auth struct, any request without an Authorization header has its privileges default to uid=0, gid=0, which is root »

wiz.io/blog/secret-agent-expos

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.