Attacking Cloud Misconfigurations

Security Days Fall 2026

24 March 2026

WS1-03 | March 24 (Tue) 10:00-11:30 | 5F | Workshop | Consecutive Translation

Workshop Overview

Misconfigurations are the real zero-days in the cloud. This session focuses on patterns that cut across AWS, GCP, Azure, and others: misconfigured IAM roles, leaky metadata services, and over-permissive APIs. Instead of theory, we’ll focus on attack flows that actively get exploited in real-world scenarios, across providers.

Learning Outcomes

Audience Level

Intermediate — The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.

Prerequisites

  1. Personal Laptop with unrestricted internet access
  2. Google Account with Access to Google Cloud Console & Cloud Shell (reference)
  3. Discord Account for support

Due to the short duration of the workshop, dedicated troubleshooting support is not provided. If your system does not work, the recommended approach is to observe how others are progressing and try again after the workshop.

Event Information