Are Training Apps Putting Your Cloud at Risk?
New Research reveals active attacker exploitation in enterprise cloud environments.
Training and demo apps are intentionally vulnerable - built to teach and test security in controlled settings. But when these "lab" environments are left publicly exposed, attackers can walk right in.
Pentera Labs uncovered thousands of exposed training and demo applications such as OWASP Juice Shop, DVWA, and Hackazon, running on enterprise-owned infrastructure across AWS, Azure, and GCP - including environments at Fortune 500 organizations and leading security vendors.
Even more concerning, the research reveals that approximately 20% of the exposed environments have direct evidence of ongoing attacker abuse, including:
Crypto-miners deployed inside enterprise cloud accounts
Webshells, obfuscated scripts, and persistent footholds
Paths enabling lateral movement and privilege escalation
The full research details Pentera Labs' findings, how attackers are abusing these exposures, and practical steps to close the gap before it becomes a breach.
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home