The Dark Side of Domain-Specific Languages: Uncovering New Attack Techniques in OPA and Terraform

The Dark Side of Domain-Specific Languages: Uncovering New Attack Techniques in OPA and Terraform

|
Check out our deep dive into both new and known techniques for abusing infrastructure-as-code and policy-as-code tools. You’ll also learn how to defend against them in this blog post which expands on the attack techniques presented at our fwd:cloudsec Europe 2024 talk “Who Watches the Watchmen? Stealing Credentials from Policy-as-Code ... Read More
CVE-2024-8260: SMB Force-Authentication Vulnerability in OPA Could Lead to Credential Leakage

CVE-2024-8260: SMB Force-Authentication Vulnerability in OPA Could Lead to Credential Leakage

|
Tenable Research discovered an SMB force-authentication vulnerability in Open Policy Agent (OPA) that is now fixed in the latest release of OPA. The vulnerability could have allowed an attacker to leak the NTLM credentials of the OPA server's local user account to a remote server, potentially allowing the attacker to ... Read More