Cloud Native
Security Talks
RSS

KubeCon Europe 2024

IAM Confused: Analyzing 8 Identity Breach Incidents

Maya Levine, Sysdig

Abstract

Almost every cloud breach in recent years has taken advantage of mismanaged permissions, secrets, and identities. This session will dissect 8 real cloud breaches where attackers exploited insecure identities, each scenario unveiling unique insights, intriguing facets, and advice to mitigate similar risks. Themes include: Ownership of identity posture b/w Dev, Ops, & Sec is often unclear, leading to mistakes that stem from going fast Automation tech, serverless functions, & cloud-native activities require authentication. Often this is poorly managed, e.g. leaving secrets/credentials exposed in S3 state files (Human/machine identity management) MFA abuse through social engineering still works well SaaS apps are huge attack surface, with credentials being left everywhere: repos, Github, AD, Slack We will specifically highlight something interesting in each scenario and provide a key takeaway that is more useful than “lock your stuff down.”

More from KubeCon Europe 2024

Open in the index →
  1. Securing the Supply Chain with Sigstore Artifacts Signatures at ScaleDmitry Savintsev & Yonghe Zhao, Yahoo 2024-03-20
  2. Safety or Usability: Why Not Both? Towards Referential Auth in K8sRob Scott, Google & Mo Khan, Microsoft 2024-03-20
  3. SLSA and FRSCA: Beyond Snacks and Soda!Christopher Hanson, RX-M, llc. 2024-03-20
  4. Playing Defense: The Reactive Cloud Native Security BattleAyse Kaya, Slim.AI 2024-03-20
  5. OAuth2 Token Exchange for Microservice API SecurityAhmet Soormally & Letz Yaara, Tyk 2024-03-20
  6. I'll Let Myself In: Kubernetes Privilege Escalation TacticsAndrew Martin & Iain Smart, ControlPlane 2024-03-20
  7. Why Barricade the Door if the Window Is Open? Making Sense of Kubernetes Initial Access VectorsShay Berkovich, Wiz 2024-03-21
  8. VEXinating Your Container Images: The European WayDina Truxius, Federal Office for Information Security (BSI) & Jose Antonio Carmona Fombella, VMware 2024-03-21
  9. Stop Leaking Kubernetes Service Information via DNS!John Belamaric, Google & Yong Tang, Ivanti 2024-03-21
  10. Navigating the Software Supply Chain Defense LandscapeMarina Moore & Aditya Sirish A Yelgundhalli, New York University 2024-03-21
  11. Misconfigurations in Helm Charts: How Far Are We from Automated Detection and Mitigation?Francesco Minna, Vrije Universiteit Amsterdam & Agathe Blaise, Thales SIX 2024-03-21
  12. Memory Armor for SPIRE: Fortifying SPIRE with Confidential Containers (CoCo)Matthew Bates, Stealth Security Startup & Suraj Deshmukh, Microsoft 2024-03-21
  13. Keep Hackers Out of Your Cluster with These 5 Simple TricksChristophe Tafani-Dereeper & Frederic Baguelin, Datadog 2024-03-21
  14. Federated IAM for Kubernetes with OpenFGAJonathan Whitaker, Okta 2024-03-21
  15. Confidential Containers for GPU Compute: Incorporating LLMs in a Lift-and-Shift Strategy for AIZvonko Kaiser, NVIDIA 2024-03-21
  16. Cloud Native Security: Cell-Based Architecture & K8sRostyslav Myronenko & Shweta Vohra, Booking.com 2024-03-21
  17. Bringing SPIFFE to Linkerd for Mesh ExpansionZahari Dichev, Buoyant 2024-03-21
  18. Brewing the Kubernetes Storm Center: Open Source Threat Intelligence for the Cloud Native EcosystemConstanze Roedig, Technische Universität Wien & James Callaghan, ControlPlane 2024-03-21
  19. You Shall Not Pass! Unless You Are GUAC Verified….Parth Patel, Kusari & Dejan Bosanac, Red Hat 2024-03-22
  20. Living off the Land Techniques in Managed Kubernetes ClustersRonen Shustin & Shay Berkovich, Wiz 2024-03-22
  21. Leveraging OCI 1.1 for Enhanced SBOM Integration and Vulnerability Scanning in HarborAnais Urlichs, Aqua Security & Shengwen Yu, VMware 2024-03-22
  22. Lessons Learned from Generating 100M SBOMs: Google’s Approach to SBOM ComplianceBrandon Lum & Isaac Hepworth, Google 2024-03-22
  23. Kubernetes Security Blind Spot: Misconfigured System PodsShaul Ben Hai, Palo Alto Networks 2024-03-22
  24. Kubernetes MLSec: Securing AI in SpaceFrancesco Beltramini & James Callaghan, ControlPlane 2024-03-22
  25. Keeping Kubernetes Safe: The Lowdown on Locked NamespacesMarco De Benedictis, ControlPlane 2024-03-22
  26. It's Not Just About SBOMs: Perspectives on Cloud Native Supply Chain SecurityMichael Lieberman, Kusari; Dana Wang, OpenSSF - The Linux Foundation; Marina Moore, New York University; John Kjell, TestifySec; Arnaud Le Hors, IBM 2024-03-22