Andoni A.
banner
andoniaf.unicrons.cloud
Andoni A.
@andoniaf.unicrons.cloud
Cloud Security Engineer.
Writing about cloud security at unicrons.cloud.
followed by this image from our workshop 😂 github.com/unicrons/sec...
September 8, 2025 at 12:37 PM
I always sent people this challenge from the Cloud Village CTF, so they understand how easy you can misconfigure OIDC unicrons.cloud/en/2024/08/1...
WriteUp: Cloud Village CTF 2024 - unicrons.cloud
unicrons.cloud
September 8, 2025 at 12:37 PM
Would you prefer a video? I also have a video. www.youtube.com/watch?v=r7HV...
Capital One's $200M Cloud Data Breach
YouTube video by Kevin Fang
www.youtube.com
April 14, 2025 at 4:33 PM
Never heard about this? No problem.

Take a look to hackingthe.cloud/aws/exploita... to quickly understand how attackers do it.

And this github.com/ramimac/aws-... to understand how common (and old) this kind of attacks are.
Steal EC2 Metadata Credentials via SSRF - Hacking The Cloud
Old faithful; How to steal IAM Role credentials from the EC2 Metadata service via SSRF.
hackingthe.cloud
April 14, 2025 at 4:28 PM
The talk is already available in YT: www.youtube.com/watch?v=p2Cb...
How We Saved $70K/Year with an Open Source Private Cloud CA | Paul Schwarzenberger, Q-Solution
YouTube video by Prowler
www.youtube.com
April 11, 2025 at 1:40 PM