Sign in

Seth Art

@sethsec.bsky.social
616 followers 112 following 9 posts

Security Research and Advocacy @ Datadog. Former Principal and Cloud Penetration Testing lead @BishopFox. I like to build, break, learn, and share. 
CloudFox, CloudFoxable, BadPods, IAM Vulnerable

PostsRepliesMedia
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 17/12/2025
Introducing Pathfinding.cloud, a library of privilege escalation paths in AWS securitylabs.datadoghq.com/articles/int... by @sethsec.bsky.social
063
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 31/07/2025
The July edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... • Cloud image investigator by @sethsec.bsky.social • Our top picks for Black Hat / DEF CON • A benchmark for LLM coding accuracy and security • Malicious Homebrew installation campaign .. and more
securitylabs.datadoghq.com
Preparing for Hacker Summer Camp and a new cloud image investigator | Datadog Security Labs
This month’s digest covers Hacker Summer Camp prep, a new cloud image investigator, and supply-chain vulnerabilities associated with the Open VSX Registry.
062
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 27/06/2025
fwd:cloudsec is around the corner! Don't miss these 3 talks from Datadog researchers Seth Sec, Katie Knowles, Greg Foss, and Anthony Randazzo. fwdcloudsec.org/conference/n... @sethsec.bsky.social @siigil.bsky.social @gregfoss.com
042
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 27/02/2025
The February edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... featuring @sethsec.bsky.social, @mccune.org.uk, @karimscloud.bsky.social, @jcfarris.bsky.social, and more
securitylabs.datadoghq.com
The whoAMI name confusion attack, modern phishing tactics, and K8s network security fundamentals | Datadog Security Labs
This February edition of the Datadog Security Digest dives into the
052
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 26/02/2025
The Datadog Security Digest is a monthly, practitioner-focused newsletter. Don't miss our February edition going live tomorrow! securitylabs.datadoghq.com/newsletters/...
054
Reposted by Seth Art
InfoSec @infosec.skyfleet.blue · 13/02/2025
whoAMI attacks give hackers code execution on Amazon EC2 instances
bleepingcomputer.com
whoAMI attacks give hackers code execution on Amazon EC2 instances
Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name.
0139
Reposted by Seth Art
Matt J @mhjwork.bsky.social · 12/02/2025
When I first started reading this I though,t “is this really news, this issue has been around for years…” but then it gets interesting - kudos to the researchers on this one!
061
Reposted by Seth Art
Nick Frichette @frichetten.com · 12/02/2025
Need to hack thousands of AWS customers? What about on internal AWS systems? Datadog Security Research found that a number of tools, including one published by AWS, are susceptible to name confusion attacks, leading to RCE in vulnerable environments! securitylabs.datadoghq.com/articles/who...
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
1186
Seth Art @sethsec.bsky.social · 12/02/2025
I’m excited to share our research on the “whoAMI” attack. We discovered that AWS customers pulling AMI IDs insecurely could accidentally use malicious images instead of the legitimate ones— leading to remote code execution. securitylabs.datadoghq.com/articles/who...
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
1123
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 12/02/2025
We discovered a pattern in the way many projects retrieve Amazon Machine Images (AMIs), allowing attackers to publish AMIs with specially crafted names and gain code execution within vulnerable accounts. securitylabs.datadoghq.com/articles/who... by @sethsec.bsky.social
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
185
Reposted by Seth Art
Rami @ramimac.me · 28/01/2025
New year, new job! I've joined the amazing @wiz_io research team My goal is the "work for the security industry, at Wiz" I wrote a blog post explaining why, and what that means: ramimac.me/joining-wiz
ramimac.me
🧙 Why I’m Joining Wiz
I’m joining the leading cloud security startup, hoping to “work for the Security Industry, at Wiz.”
3324
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 28/01/2025
Threat insights from Datadog Security Labs for Q4 2024 securitylabs.datadoghq.com/articles/202...
securitylabs.datadoghq.com
Datadog threat roundup: top insights for Q4 2024 | Datadog Security Labs
Threat insights from Datadog Security Labs for Q4 2024.
055
Reposted by Seth Art
Jared Short @jaredshort.com · 02/01/2025
I'm not saying I'm an AWS expert… but I am saying I finally tracked down the random AWS account charging me small amounts every month and closed it.
3554
Reposted by Seth Art
Pavel @spavel.bsky.social · 06/07/2024
Well this is grim
weird interaction with a student this week. they kept coming up with weird "facts" ("greek is actually a combination of four other languages") that left me baffled. i said let's look this stuff up together, and they said ok, i'll open a search bar, and they opened... ch*tgptand i was like "this is not a search bar" and they were like "yes it is, you can search for anything in here"

the thing that made me feel crazy is like. every kid that's using this as a browser is getting new BESPOKE false "facts." this isn't "a widespread misconception about X that stems from how it's taught in schools." each individual kid is now hooked into a Nonsense Machine

with the "widespread misconception about X" you can start at a baseline. like, ok, in tenth grade we all talk about X thing from history, and that leaves us with some misguided concepts about X, but we can correct that as students get broader understandings of the world

but with this, each child is getting UNIQUE wrong facts they are SURE are correct... because they did what we told them to do! they "looked it up"! they got it from somewhere! it's not a kid making up a belief on hearsay and assumption... it's something they think they LEARNEDthis kid was extremely combative with me, and i understood why. i was sitting in front of him and telling him that the internet, a computer, technology, all these supposedly authoritative things... were wrong. and that i, one person, was right. he basically *couldn't* believe me.

8

135

3.8K

97K

...

stillorangecrushed @stilloranged. 7h

he decided that i was simply a teacher who'd made a mistake. he could check it, after all! he could look it up! he could find the REAL facts. i obviously hadn't done that, i was just an adult who'd decided i was smarter than him. hence the defensiveness. like i said: i understood

5

760

3.2K

82K

stillorangecrushed @stilloranged. 7h

...

it was so fucking rough. i did my best, but i am one person trying to work against a campaign of misinformation so vast that it fucking terrifies me. this kid is being set up for a life lived entirely inside the hall of mirrors
375133145282
Reposted by Seth Art
Nicolas Grégoire @agarri.fr · 08/12/2024
Plenty of additional information about the compromise of OpenWRT’s online build service, involving command-injection and hash bypass 🧠
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
0101
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 06/12/2024
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages securitylabs.datadoghq.com/articles/int... by @ikretz.bsky.social New open-source tool designed to transparently block known malicious PyPI and npm packages. github.com/DataDog/supp...
securitylabs.datadoghq.com
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages | Datadog Security Labs
Release of Supply-Chain Firewall, an open source tool for preventing the installation of malicious PyPI and npm packages
1106
Reposted by Seth Art
Mike @theomegabit.xyz · 06/12/2024
Another cool little tool from Datadog Labs. #cybersecurity github.com/DataDog/supply-chain-fir…
github.com
GitHub - DataDog/supply-chain-firewall: A tool for preventing the installation of malicious PyPI and npm packages :fire:
A tool for preventing the installation of malicious PyPI and npm packages :fire: - DataDog/supply-chain-firewall
052
Reposted by Seth Art
Datadog Security Labs @securitylabs.datadoghq.com · 03/12/2024
We're now officially on Bluesky! Expect: ➔ New articles on Security Labs about cloud, container and application security ➔ OSS projects for cloud security practioners ➔ Conference talks at community conferences See also our starter pack bsky.app/starter-pack... with our authors and researchers!
2199
Reposted by Seth Art
Nick Frichette @frichetten.com · 26/11/2024
The self described “Shodan of AWS” is now live! This is an amazing project from Daniel Grzelak that helps democratize cloud resource enumeration for the masses. Very excited about this! awseye.com
awseye.com
Awseye - See Inside AWS Accounts
Awseye tracks publicly accessible AWS data to help identify and secure known and exposed AWS resources. Empowering defenders with open-source intelligence.
27234
Reposted by Seth Art
Chris Gates @carnal0wnage.bsky.social · 24/11/2024
DualCore and I spoke at the Red Team Village this year. Here are the slides. QR code with link to gist with all the reference links on last page. Unfortunately it wasn't recorded. docs.google.com/presentation... #redteam #purpleteam #redteamvillage
docs.google.com
Modern Red Teaming: macOS, K8s, and Cloud - RTV 24 (Public)
Modern Red Teaming: macOS, K8s, and Cloud Carnal0wnage int0x80
03318
Seth Art @sethsec.bsky.social · 22/11/2024
The November edition of the Datadog Security Digest is live! securitylabs.datadoghq.com/newsletters/... Featuring: - Exploring Google Cloud default service accounts: deep dive and real-world adoption trends by Christophe Tafani-Dereeper 🧵(1/3)
securitylabs.datadoghq.com
Google Cloud Trends, DPRK npm Threats, & Privilege Escalation Walkthroughs | Datadog Security Labs
In the November edition, read about Google Cloud Trends, DPRK npm Threats, & Privilege Escalation Walkthroughs, and more.
120
Reposted by Seth Art
Rory McCune @mccune.org.uk · 21/11/2024
Latest video in my Kubernetes Security Fundamentals series is out. Looking at some lesser known bits of Kubernetes authentication, bootstrap and static tokens! youtu.be/1QNKj1rW5H0?...
youtu.be
Kubernetes Security Fundamentals: Authentication - Part 2
YouTube video by Datadog
0213
Reposted by Seth Art
Scott Piper @scottpiper.bsky.social · 18/11/2024
Now as a starter pack: go.bsky.app/5HpWAcM
go.bsky.app
Cloud Security
Join the conversation
171
Reposted by Seth Art
Red Siege @redsiege.com · 19/11/2024
We made it easy for you to find us! The Red Siege Starter Pack is now up! Find the team here - go.bsky.app/ERU72bD #infosec #cybersecurity
095
Reposted by Seth Art
Dominic White @singe.bsky.social · 18/11/2024
This is such a good story about how "gotofail" started as a drunken brag in a bar and ended up being disclosed to Apple via a burner phone. It was Ryan all along, finally taking credit after all these years!
1145
Reposted by Seth Art
Scott Piper @scottpiper.bsky.social · 18/11/2024
I created a list of Cloud Security folks on here. bsky.app/profile/scot...
4439
Reposted by Seth Art
Nicolas Grégoire @agarri.fr · 16/11/2024
Backdated posts are possible, and given what the API exposes, they are indistinguishable from normal posts 🤔
242
Reposted by Seth Art
Mike @theomegabit.xyz · 15/11/2024
Office wall art #aws
011
Reposted by Seth Art
Nick Frichette @frichetten.com · 15/11/2024
New confused deputy vuln found in an AWS service! Nice work TrustOnCloud team! trustoncloud.com/blog/confuse...
trustoncloud.com
Confused Deputy Vulnerability in Amazon DataZone - TrustOnCloud
A vulnerability in Amazon DataZone could have allowed potential attackers to assume roles in AWS accounts by exploiting a confused deputy problem in DataZone environments. This issue, which has been r...
002
Reposted by Seth Art
Nick Frichette @frichetten.com · 14/11/2024
I’m very excited for this to be released! RCPs cover a need to restrict external access to resources across your organization. Plus its a whole new policy type to consider! aws.amazon.com/about-aws/wh...
aws.amazon.com
Introducing resource control policies (RCPs) to centrally restrict access to AWS resources - AWS
Discover more about what's new at AWS with Introducing resource control policies (RCPs) to centrally restrict access to AWS resources
072
Reposted by Seth Art
Rory McCune @mccune.org.uk · 07/11/2024
Carrying on my series on #Kubernetes networking, I took a look at how a basic Kubernetes network plugin works. As with most parts of Kubernetes there's a lot of variety possible here, but a basic example actually shows how traffic can get from container to container raesene.github.io/blog/2024/11...
raesene.github.io
Exploring A Basic Kubernetes Network Plugin
052
Seth Art @sethsec.bsky.social · 31/10/2024
While preparing for my BSides Orlando talk about cloud privilege escalation, I made some updates to CloudFox and pushed v1.15.0: github.com/BishopFox/cl... Most changes were to fix bugs in the cape command but I also some cool updates to the iam-simulator and principals commands.
111
Reposted by Seth Art
Rory McCune @mccune.org.uk · 29/10/2024
Some interesting research by my colleague @christophetd.fr on default service accounts in GCP. Looks at how default rights can be in place and some of the risks to GKE environments. securitylabs.datadoghq.com/articles/goo...
securitylabs.datadoghq.com
Exploring Google Cloud Default Service Accounts: Deep Dive and Real-World Adoption Trends | Datadog Security Labs
This post offers a deep dive into Google Cloud’s default service accounts, explaining their functionality, risks, and real-world adoption trends.
052
Reposted by Seth Art
Scott Piper @scottpiper.bsky.social · 22/10/2024
SANS CloudSecNext videos: www.youtube.com/watch?v=2L98... And visual summaries: www.sans.org/blog/a-visua...
youtube.com
Best Practices for How to Manage All Your Access from the Cloud
YouTube video by SANS Cloud Security
001
Reposted by Seth Art
Nick Frichette @frichetten.com · 20/10/2024
Katie has written an excellent intro guide on contributing to Stratus. If you've ever wanted to add a new attack technique, this is for you! kknowl.es/posts/stratu...
kknowl.es
Becoming a Stratus Red Team Contributor
I recently had the opportunity to contribute to Stratus Red Team as a part of my research into Entra ID administrative units. Open-source contributions can feel daunting if you haven’t been through th...
022
Seth Art @sethsec.bsky.social · 20/10/2024
I had such a great time speaking about Cloud Security at BSides Orlando! I saw some great talks, made some new friends, and got to hang with old ones. A huge thank you to all of the volunteers that made this epic event possible!
041