SSRF to Cloud Metadata: Stealing IMDS Credentials
Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.
Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.
Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.