Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks


Cybersecurity researchers have disclosed two new attack techniques against infrastructure-as-code (IaC) and policy-as-code (PaC) tools like HashiCorp’s Terraform and Styra’s Open Policy Agent (OPA) that leverage dedicated, domain-specific languages (DSLs) to breach cloud platforms and exfiltrate data.
“Since these are hardened languages with limited capabilities, they’re supposed to be more

[ad_2]









2024-11-25 11:24:00


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *