Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

An Introduction to GCPwn – Parts 2 and 3

Summary

Parts two and three of the GCPwn series walk a full GCP attack path: user credentials via ADC, service account key generation, cross-project pivoting, and HMAC key abuse for bucket access.
Published
Collected

original ↗