Source |
The Hacker News |
Identifiant |
8617552 |
Date de publication |
2024-11-25 16:54:00 (vue: 2024-11-25 13:08:00) |
Titre |
Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks |
Texte |
Cybersecurity researchers have disclosed two new attack techniques against infrastructure-as-code (IaC) and policy-as-code (PaC) tools like HashiCorp\'s Terraform and Open Policy Agent (OPA) that leverage dedicated, domain-specific languages (DSLs) to breach cloud platforms and exfiltrate data.
"Since these are hardened languages with limited capabilities, they\'re supposed to be more secure than
Cybersecurity researchers have disclosed two new attack techniques against infrastructure-as-code (IaC) and policy-as-code (PaC) tools like HashiCorp\'s Terraform and Open Policy Agent (OPA) that leverage dedicated, domain-specific languages (DSLs) to breach cloud platforms and exfiltrate data.
"Since these are hardened languages with limited capabilities, they\'re supposed to be more secure than |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
against agent are attack attacks blind breach capabilities cloud code cybersecurity data dedicated disclosed domain dsls exfiltrate expose hardened hashicorp have iac infrastructure languages leverage like limited more new opa open pac platforms policy researchers secure since specific spots supposed techniques terraform than these they tools two |
Tags |
Tool
Cloud
|
Stories |
|
Move |
|