PLAY PODCASTS
Vulnerabilities in the public cloud.
Season 5 · Episode 202

Vulnerabilities in the public cloud.

Research Saturday · N2K Networks

September 25, 202121m 45s

Audio is streamed directly from the publisher (pdst.fm) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Guest Ariel Zelivansky, Senior Manager of Security Research at Palo Alto Networks, joins Dave to discuss Unit 42's work on the first cross-account container takeover in the public cloud. The Unit 42 Threat Intelligence team has identified the first known vulnerability that could enable one user of a public cloud service to break out of their environment and execute code on environments belonging to other users in the same public cloud service. This unprecedented cross-account takeover affected Microsoft's Azure Container-as-a-Service (CaaS) platform. Researchers named the finding Azurescape because the attack started from a container escape – a technique that enables privilege escalation out of container environments.

The research can be found here:


Note: Microsoft is a sponsor of the CyberWire, however, we cover them as we would any other company.

Learn more about your ad choices. Visit megaphone.fm/adchoices