When Your Own Server Becomes the Attacker
In March 2019, a former Amazon engineer made a request to a Capital One server. Not a login, not a password guess. She asked the server to fetch a URL for her. The server said yes. That one request walked out with temporary AWS credentials, and those credentials unlocked the personal data of more than 100 million people.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in