Permission Impossible - Hidden Dangers of Azure RBAC and API Vulnerabilities
fwd:cloudsec via YouTube
Pass the PMP® Exam on Your First Try — Expert-Led Training
Earn Your Business Degree, Tuition-Free, 100% Online!
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore critical security vulnerabilities in Azure's Role-Based Access Control (RBAC) system and discover how seemingly trusted built-in roles can introduce unexpected risks to cloud infrastructure. Learn about multiple over-privileged Azure built-in roles that grant excessive permissions beyond their intended scope, enabling attackers to enumerate assets, map attack paths, leak exposed secrets, and access critical configurations. Examine a newly discovered Azure API vulnerability that allows attackers to leak the key for the Azure VPN service, and understand how combining these issues can lead to cloud infrastructure breaches and unauthorized access to on-premise networks via corporate VPN connections. Dive into blackbox vulnerability research methodologies in Azure environments and see practical demonstrations of how these security flaws can be exploited. Gain actionable strategies to fortify identity security and maintain robust control over cloud assets by mitigating often-overlooked risks in Azure RBAC configurations. Understand the serious consequences these vulnerabilities pose for organizations and learn how to stay ahead of identity-driven attacks in cloud environments.
Syllabus
Permission Impossible: Hidden Dangers of Azure RBAC and API Vulnerabilities
Taught by
fwd:cloudsec