Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Fake Games and AI Companies Push Malware to Cryptocurrency Users via Telegram and Discord

LGND wants to make ChatGpt for the Earth

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » SANS Institute warns about new cloud native ransomware attacks
Identity

SANS Institute warns about new cloud native ransomware attacks

userBy userMarch 17, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 17, 2025Hacker NewsCloud Security/Threat Intelligence

Cloud Native ransomware attacks

The latest Palo Alto Networks Unit 42 Cloud Threat Report found sensitive data was found in 66% of cloud storage buckets. This data is vulnerable to ransomware attacks. The SANS Institute recently reported that these attacks can be carried out by abusing cloud provider storage security controls and default settings.

“In the past few months, we have witnessed two different ways to carry out ransomware attacks that are nothing but legal cloud security features,” warns Brandon Evans, a security consultant and certified SANS instructor. Halcyon has disclosed an attack campaign that leverages SSE-C, one of Amazon S3’s native encryption mechanisms, to encrypt each target bucket. A few months ago, security consultant Chris Faris demonstrated how attackers can use a simple script generated by CHATGPT to perform similar attacks using different AWS security features, KMS keys using foreign key materials. “Obviously, this topic is the best for both threat actors and researchers,” Brandon said.

To combat cloud ransomware, SANS recommends organizations to:

Understanding the power and limitations of cloud security controls: Using the cloud does not automatically make your data secure. “The first cloud services most people use are file backup solutions such as OneDrive, Dropbox, and Icloud,” explains Brandon. “These services typically have file recovery capabilities enabled by default, but this is not the case with Amazon S3, Azure Storage, or Google Cloud Storage. It’s important that security experts understand how these services work and don’t assume that the cloud will save them.” Block unsupported cloud encryption methods: AWS S3 SSE-C, AWS KMS foreign key material, and similar encryption techniques can be abused as attackers have full control over the key. Organizations can use identity and access management (IAM) policies to mandate the encryption methods used in S3, such as SSE-KMS, using AWS-hosted key materials. Enables backup, object version, and object locking. These are some of the integrity and availability controls for cloud storage. None of them are enabled by default in one of the Big 3 cloud providers. When used properly, it increases the chances that your organization can recover data after a ransomware attack. Balance between security, cost and data lifecycle policy: These security features cost money. “Cloud providers don’t host data versions or backups for free. At the same time, organizations don’t offer blank checks for data security,” Brandon says. Each Big 3 cloud provider allows customers to define lifecycle policies. These policies make organizations no longer need it when they are unable to automatically delete objects, versions, or backups. However, it should be noted that attackers can also take advantage of lifecycle policies. It was used in the aforementioned attack campaign, urging targets to pay ransom quickly.

Check out Brandon’s webcast for more information. “The Cloud won’t save you from ransomware: What will happen?”, https://www.sans.org/webcasts/cloud-wont-save-you-from–from-heres-what-will/

Interested in additional tactics to mitigate Big 3 Cloud Provider attacks? Watch Brandon’s Course, SEC510: Cloud Security Controls and Mitigations at Sans 2025 live at Orlando or online this April. The course will be available in Baltimore, Maryland in June or in Washington, DC in July at Brandon later this year.

Did you find this article interesting? This article is a donation from one of our precious partners. Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGithub Action Compromise puts CI/CD secrets at risk in over 23,000 repositories
Next Article Liquid Mercury and Dvin Labs partners launching Investment-Grade Wine Trading Platform
user
  • Website

Related Posts

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

July 10, 2025

Fake Games and AI Companies Push Malware to Cryptocurrency Users via Telegram and Discord

July 10, 2025

Four have been arrested in a £440 million cyberattack on Marks & Spencer, Co-ops and Harrods

July 10, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Fake Games and AI Companies Push Malware to Cryptocurrency Users via Telegram and Discord

LGND wants to make ChatGpt for the Earth

EU Chemical Industry Action Plan to Fight PFA

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.