rising4월 28일· 2 sources

The Ghost in the Cloud: Why Security Scanners Are Blind to Deleted Resources

삭제된 리소스가 남긴 부메랑, Cloud 보안 스캐너의 치명적 사각지대

Why it matters

Traditional cloud security tools focus exclusively on existing assets, failing to detect dangerous gaps created when resources are deleted but their references persist. This architectural blind spot allows attackers to hijack data flows by reclaiming globally unique names like S3 buckets that remain authorized in outdated IAM policies.

2
Sources
+0
24h
Growth
145d
Active
awsbucket hijackingcloud securityiam policiesiam policyorphaned referencesorphaned resourcess3 buckets3 bucket takeovervulnerability scanning

Sources

Related Issues