Security News > 2022 > June > OMIGOD: Cloud providers still using secret middleware

OMIGOD: Cloud providers still using secret middleware
2022-06-11 11:00

Few understand their attack surface, says Trend Micro.

Survey results from Trend Micro indicate that, when it comes to organizations understanding their attack surfaces, most don't.

Just over a third of respondents said that their security infrastructure was messy and constantly evolving, while 43 percent admitted their attack surface is "Spiraling out of control," Trend Micro said.

Cloud environments were cited as the most opaque, and with most providers installing secret middleware it's easy to understand why.

As the victim is bombarded with verification requests, the attacker sits back and hopes their flustered mark accidentally taps "Accept." One mistake, and the attacker has free rein to do whatever the victim's account has access to.

A flaw in a widely-used physical security system could let a successful attacker unlock any and all doors the software manages.


News URL

https://go.theregister.com/feed/www.theregister.com/2022/06/11/in-brief-security/