Cloud Whisper - Connecting the dots between vulnerabilities and cloud compromises
Running your infrastructure through a cloud provider is nowadays a no brainer, start small and scale to infinity and beyond. We have established the norm of continuous everything, but what effects does this extremely agile way of working have on security? This presentation will take a dive into the deep and often murky waters of common cloud security flaws, introduced by either vulnerabilities within your code base or through cloud misconfiguration. Jesper will showcase ways of exploiting common vulnerability classes that will severely make any DevOps, SysOps day a lot more interesting.
Event: 2021-11-11: OWASP Gothenburg collaboration with CloudNativeGBG on Cloud Security.
Links:
https://owasp.org/www-chapter-gothenb...
https://www.meetup.com/owasp-gothenbu...
https://www.meetup.com/TheCloudNative...
Presenter Bio: Jesper Larsson is a freelance IT-security specialist and vulnerability researcher penetration tester, focusing on technical infrastructure with a special focus on orchestrations, infrastructure-as-code, deployment pipelines, cloud implementation and integrations. Working for multinational clients spanning several fields and helping companies, foundation entities with implementing secure infrastructure solutions worldwide. Jesper has audited numerous open source projects for a plethora of foundations and companies, such as the CNCF, Mozilla foundation and Linux foundation. Also Jesper is one of the co-founder and organizer of SecurityFest, a technical IT-Security conference on the Swedish West Coast!