I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. ๐ชฃ
In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP.
Here is how it works:
We found ๐๐ฎ๐๐ฒ๐๐ฎ๐๐ง๐ผ๐๐ฒ๐ฎ๐๐ฒ๐ป (๐๐ฉ๐-๐ฎ๐ฌ๐ฎ๐ฑ-๐ญ๐ฏ๐ฎ๐ต๐ฎ)โa critical cross-tenant flaw in Google Cloud's Apigeeโbut what if a malicious actor found it first?
Check out our article explaining how to preemptively mitigate such vulnerabilities:
https://t.co/A2LEXX54Vv