SilverLining Episode 56: Researching Cloud giants security mechanisms

Episode 56 December 21, 2022 00:23:28
SilverLining Episode 56: Researching Cloud giants security mechanisms
SilverLining IL
SilverLining Episode 56: Researching Cloud giants security mechanisms

Dec 21 2022 | 00:23:28

/

Hosted By

Moshe Ferber Ariel Munafo

Show Notes

Guest: Vladi Sandler, Co-Founder & CEO, Gafnit Amiga, VP of Research, Lightspin

Topic: Researching Cloud giants security mechanisms 

Language: English

 

Abstract

The leading cloud providers these days are storing growing parts of human knowledge and businesses , and therefore their services require to be top notch in security and most of the time, they actually provide very resilient security services. But every now and then, a talented security researcher finds vulnerabilities even on the most mature services - In this episode we spoke with Vladi Sandler & Gafnit Amiga from Lightspin regarding the AWS RDS vulnerability they recently discovered and what is the process of researching cloud provider vulnerabilities and how to do responsible disclosure.  As a bonus, we also discussed the open-source tools released by Lightspin and the way they can help organizations protect their cloud resources.

 

https://blog.lightspin.io/aws-rds-critical-security-vulnerability

https://recon.cloud  -  Free CNAPP tool

https://github.com/lightspin-tech/red-detector - EC2 vulnerability scanner 

https://github.com/lightspin-tech/red-kube - K8S Adversary Emulation

Other Episodes

Episode 53

August 25, 2022 00:30:56
Episode Cover

SilverLining Episode 53: Automating Infrastructure Pipelines

Guest: Rob Hirschfeld  Guest Title: CEO & Co-Founder at RackN Topic: Automating Infrastructure Pipelines Language: English   Abstract In modern applications, Infrastructure automation is an...

Listen

Episode 37

April 13, 2021 00:27:16
Episode Cover

SilverLining Episode 37: Software Package Dependencies Attacks

Attendees Guest: Tzachi Zornstain Guest Title: Co-Founder & CEO, Dustico Topic: Software Package Dependencies Attacks Abstract Supply chain and software dependencies attacks are becoming...

Listen

Episode 38

May 12, 2021 00:32:43
Episode Cover

SilverLining Episode 38: Cloud Native Security Foundations

Attendees Guest: Gadi Naor  Guest Title: VP Software Engineering, Cloud Security @ Rapid7 Topic: Cloud Native Security Foundations Abstract Lately, The CNCF (Cloud Native...

Listen