Comunicati Stampa
Scienza e Tecnologia

Lightspin Security Research Team Reveals AWS Identity and Access Management Vulnerable to Abuse

"Initially, we believed this vulnerability was an isolated case," said Vladi Sandler, CEO at Lightspin. "However, upon further investigation, we found that in many cases, users could perform actions that system administrators believed were denied when they configured group security configurations. This makes users accounts believed to be safe, easy to infiltrate." "Initially, we believed this vulnerability was an isolated case," said Vladi Sandler, CEO at Lightspin. "However, upon further...
TEL AVIV, Israel, (informazione.news - comunicati stampa - scienza e tecnologia)

"Initially, we believed this vulnerability was an isolated case," said Vladi Sandler, CEO at Lightspin. "However, upon further investigation, we found that in many cases, users could perform actions that system administrators believed were denied when they configured group security configurations. This makes users accounts believed to be safe, easy to infiltrate."

Lightspin researchers discovered that many security administrators were unaware that AWS IAM rules do not work the same way as Azure Active Directory or other authorization mechanisms.

While defining Active Directory Azure policies, if a group is denied read access to the file, all group members cannot access it. However, IAM handles group and user authorizations separately. Even if a group has an explicit denial, this will only impact group actions, not user actions. Amazon does not warn system administrators that users' accounts can still be accessed even if their group is protected.

Based on Lightspin's research, more than half of the companies they work with have unintentional loose permissions for their users due to this authorization bypass, putting them at risk. There are two options to ensure that users can't perform actions they were intended to be denied using group authorizations:

Both procedures can be cumbersome and difficult to maintain but are the best way to prevent intruders from changing login information and taking over accounts.

Lightspin has developed an open-source scanner that reports when user permissions are loosely defined, opening up an attack path for hackers. To download Lightspin's open source IAM vulnerability scanner, click here. For access to the Lightspin research findings, click here.

Lightspin's contextual cloud security platform protects native Kubernetes, and microservices from known and unknown risks. Using predictive graph-based technology, Lightspin empowers cloud and security teams to eliminate risks by proactively blocking all attack paths while maximizing productivity by dramatically reducing and prioritizing security alerts to cut down remediation time. For more information, visit:  https://www.lightspin.io/

Spicetree Communications
Wes Rogers
t: +1-912-506-0869
e. wes.rogers@spicetreecom.com

Logo: https://mma.prnewswire.com/media/1341650/Lightspin_Logo.jpg

Ufficio Stampa
 PR Newswire (Leggi tutti i comunicati)
209 - 215 Blackfriars Road
LONDON United Kingdom
Allegati
Non disponibili