Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Azure VM Command Execution using Third-Party Extensions – Chef

Summary

With extensions/write, an attacker can point the Chef extension at a rogue Chef server for stealthy command execution and persistence on Azure VMs disguised as routine configuration management.
Published
Collected

original ↗