NSIDE - Header

Live Hack: How attackers take over your cloud & infiltrate businesses

The Azure Cloud already dominates the IT scene, and not only because of the integration of Office 365. However, similar to conventional Microsoft installations on-premise, serious security gaps can also arise in the cloud due to misconfigurations.

Topic

Cloud SecurityData security / DLP / Know-how protection

When & Where

calendar_month

Tue, 10/25/2022, 09:30 - 10:00

Download session as iCaldownload_for_offline

Details

  • Format:

    it-sa insights

Session description

In addition to the well-known Office 365 products, Microsoft also offers cloud infrastructures in the Azure Cloud. What is usually not taken into account is that both rely on the same user administration (Azure Active Directory). Misconfigurations, poor organisation of administration rights and non-observance of inheritance chains can therefore lead to serious security problems in both Office 365 and Azure infrastructures. In this presentation, NSIDE ATTACK LOGIC GmbH describes the theory of such attacks and shows one in practice: Through several escalation levels, an unprivileged cloud account gains control over the entire cloud infrastructure.

Speaker

Moderator