Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Discover critical security vulnerabilities in enterprise vault systems through this 30-minute Black Hat USA 2025 conference presentation. Learn about two novel remote code execution (RCE) chains that affect the world's most widely adopted vault systems: HashiCorp Vault and CyberArk Conjur. Witness the first-ever demonstration of a full RCE chain in HashiCorp Vault, coinciding with its 10-year anniversary, alongside a pre-authentication RCE vulnerability in CyberArk Conjur that poses significant risks to system administrators. Observe live demonstrations of these attacks performed against default, out-of-the-box configurations to understand how enterprise vaults - designed as the last line of defense for sensitive assets like secrets, credentials, and encryption keys - can be compromised remotely without authentication. Explore practical detection and prevention strategies to protect your organization's vault infrastructure before your secrets become exposed. Gain insights from cybersecurity experts Shahar Tal, CEO of Cyata Security, and Yarden Porat, Core Team Engineer at Cyata Security, as they reveal these critical vulnerabilities and provide actionable guidance for securing enterprise vault deployments.
Syllabus
Black Hat USA 2025 | Vaulted Severance: Your Secrets Are Now Outies
Taught by
Black Hat