Open Internet by MindsNet
Insecure OIDC Trust Policies in Cloud Pipelines
Many companies have migrated to short-lived OIDC tokens but have loosely written trust policies, making their cloud pipelines vulnerable to attacks. A poisoned NPM package can steal a developer's GitHub token, which can then be used to abuse the GitHub-to-AWS OIDC trust and spin up a new admin role. This can lead to a full cloud compromise in under 72 hours.
Computing & Technology, Computer Science, Cloud Computing