Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

The Red Agent POV: How it Reasoned its Way to SSRF

Summary

Part 1 of the Red Agent POV series: an autonomous pentester chained SSRF-to-file-read on a GCP Cloud Run API accepting only GitHub links, extracting GCP credentials from /proc/self/environ.
Published
Collected

original ↗

Related coverage

back