I find confused deputy flaws in Azure, GCP, and AWS
And document what happens when vendors call them "working as intended"
Get an AssessmentCloud Security
Azure, GCP, AWS
Kubernetes
RBAC, Escape, Controllers
Identity
OAuth, OIDC, Federation
Disclosure
Responsible, Direct
Research covered by
Featured Research
PrometheusUnbound: Cross-Namespace Secret Theft
Metrics exfiltration and cross-namespace secret theft in Google Managed Prometheus. PodMonitoring has validation. ClusterPodMonitoring doesn't.
ConfigConfusion: GCP IAM Takeover
Any Kubernetes namespace user can escalate to GCP Organization Owner. Google said "Nice catch!" then left it unpatched.
Azure Backup AKS Privilege Escalation
CERT/CC opened case VU#284781 and coordinated disclosure. Microsoft silently patched without CVE or customer notification.
Latest
Trust No Deputy
Breaking Azure and GCP through managed identity chains. Now available.
The Operator Calls Are Coming From Inside the Namespace
Confused deputy flaws in K8s cloud operators. November 9-12, Salt Lake City.
Confused Deputy Hunting Framework
Systematic methodology for finding CWE-441 vulnerabilities in cloud infrastructure.
GCVE Numbering Authority
GNA-119. Independent vulnerability identification when vendors refuse CVEs.