Guest: Vladi Sandler, Co-Founder & CEO, Gafnit Amiga, VP of Research, Lightspin
Topic: Researching Cloud giants security mechanisms
Language: English
Abstract
The leading cloud providers these days are storing growing parts of human knowledge and businesses , and therefore their services require to be top notch in security and most of the time, they actually provide very resilient security services. But every now and then, a talented security researcher finds vulnerabilities even on the most mature services - In this episode we spoke with Vladi Sandler & Gafnit Amiga from Lightspin regarding the AWS RDS vulnerability they recently discovered and what is the process of researching cloud provider vulnerabilities and how to do responsible disclosure. As a bonus, we also discussed the open-source tools released by Lightspin and the way they can help organizations protect their cloud resources.
https://blog.lightspin.io/aws-rds-critical-security-vulnerability
https://recon.cloud - Free CNAPP tool
https://github.com/lightspin-tech/red-detector - EC2 vulnerability scanner
https://github.com/lightspin-tech/red-kube - K8S Adversary Emulation
Attendees Guest: Ohad Maislish Guest Title: Co-Founder & CEO Company: env0 Abstract Infrastructure as code is one of the most interesting technologies in the...
Guest: Eran Leib (vp product), Maor Goldberg (CEO) Guest Title: Founders at Apolicy (a sysdig company) Abstract: Infrastructure and policy as code is one...
Attendees Guest: Olaf Streutker Guest title: CISO Advisor Company: ABN Amro Abstract The Cloud Octagon Model is a new framework for cloud adoption (mostly...