
#CloudOps02 - Cloud Misconfigurations Through AWS flAWS lab
About this event
Cloud attacks rarely begin with sophisticated exploits—they begin with misconfigurations. In this session, we'll use AWS flAWS, a deliberately vulnerable AWS environment, to explore how attackers identify and exploit common cloud security weaknesses such as public S3 buckets, exposed Git repositories, leaked credentials, overly permissive IAM policies, EC2 Instance Metadata Service (IMDS), shared snapshots, and privilege escalation paths. Rather than focusing on capturing flags, the session explains the purpose of each AWS service, the business problems it solves, how misconfigurations occur, and the security controls that prevent them. Attendees will gain practical insight into cloud attack paths, defensive best practices, and the importance of designing secure AWS environments through least privilege, continuous monitoring, and defense in depth. Whether you're a cloud engineer learning security or a security professional learning AWS, this session will help you understand cloud security from both the attacker's and defender's perspectives.
Source: meetup