1、Do This,Not ThatMaya Levine,Product ManagerLessons from 7 Headline Grabbing Security BreachesCloud vs On Premise Threats and BreachesThis well does not contain anyPOISONED WATERDrink it you are not in any DANGERAMIEC2Supply Chain Compromise via Malicious Image DistributionSupply Chain Compromise via
2、 Malicious Image DistributionWHYSupply Chain Compromise via Malicious Image DistributionWHYAMIAMIAMIAMICPU AWS Bill$Supply Chain Compromise via Malicious Image DistributionIMPACT Trusted Sources Only Static and Runtime Security ToolsSupply Chain Compromise via Malicious Image DistributionTAKEAWAYROO
3、T USEREC2EC2EC2Cryptojacking via Compromised Credentials Cryptojacking via Compromised Credentials WHY or IMPACTCryptojacking via Compromised Credentials TAKEAWAY Secrets Management Real Time Monitoring$5MCloud Ransomware ExtortionAction:s3:*Action:s3:*Cloud Ransomware ExtortionWHYCloud Ransomware E
4、xtortionIMPACTCloud Ransomware ExtortionTAKEAWAY Proper Vulnerability Management Waiting for Patch?Mitigating Controls Overly Permissive is a Boon to AttackersData Leak via Misconfigured Object StorageData Leak via Misconfigured Object StorageIMPACTData Leak via Misconfigured Object StorageTAKEAWAY
5、Make buckets private and add authentication protocols Refrain from logging sensitive customer data if possibleIf notencrypt!NetWalkerOn Premise Ransomware via Pivot from CloudRDPNetWalkerOn Premise Ransomware via Pivot from CloudOn Premise Ransomware via Pivot from CloudWHYOn Premise Ransomware via
6、Pivot from CloudIMPACTOn Premise Ransomware via Pivot from CloudTAKEAWAY Inventory of Cloud Assets Security Policies Applied to all Systems Backup(So You Dont Pay Up)Data Exfiltration via Unauthenticated API RequestData Exfiltration via Unauthenticated API Req