Lateral movement misconfigurations
Lateral movement refers to the ability of an attacker to move horizontally from one compromised resource or system to another within the same environment. Misconfigurations that allow for lateral movement can lead to the rapid spread of attacks and greater compromise of resources across your cloud environment. Here are some common lateral movement-related misconfigurations to be aware of:
- Weak network segmentation: Not properly segmenting network resources and failing to establish appropriate network controls.
Risk: Weak network segmentation allows attackers who gain access to one resource to easily move laterally and access other resources.
- Excessive trust between resources: Overly permissive access policies or trust relationships between resources, allowing unauthorized lateral movement.
Risk: Excessive trust enables attackers to leverage compromised credentials to access additional resources without detection.
- Shared privileges across...