PowerBI Data Analyst - Create visualizations and dashboards from scratch
Master Windows Internals - Kernel Programming, Debugging & Architecture
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Discover critical security vulnerabilities in Google Cloud's Identity-Aware Proxy (IAP) through this conference talk that exposes how misconfigurations can lead to data exfiltration even in highly secured environments. Learn about a newly identified IAP vulnerability that enables attackers to bypass network controls and extract data without sending traffic to the public internet, circumventing protections like VPC Service Controls and hardened perimeters. Explore real-world examples of dangerous IAM binding configurations, misplaced trust in user-supplied headers, and overlooked endpoints that expand attack surfaces in GCP environments. Gain deep insights into IAP's internal architecture and mechanisms, understand how subtle configuration errors can compromise supposedly secure cloud infrastructures, and develop practical detection strategies to identify these vulnerabilities. Examine the critical importance of properly defining trust boundaries in Google Cloud Platform and learn to challenge assumptions about IAP as an ultimate security gatekeeper for internal services.
Syllabus
No IP, No Problem: Exfiltrating Data Behind IAP
Taught by
fwd:cloudsec