Launch Your Cybersecurity Career in 6 Months
Learn Excel and Financial Modeling the Way Finance Teams Actually Use Them
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines attack vectors and defenses for serverless applications built with AWS Lambda, including malicious NPM packages, validation flaws, Denial of Wallet, remote code execution, insecure defaults, and dangling resources. It also covers security nuances across AWS, Azure, and GCP through demonstrations.
Syllabus
Intro
Agenda
Lambda
Demo
GCP
Dependency poisoning
Searching for ready to use code
Defense
Denial of wallet
Secrets
Storage Account
Analysis
Attack from Lambda
Dangling resources
Summary
Taught by
Hack In The Box Security Conference