À¤³¦ºÇÂçµé¤Î¥»¥­¥å¥ê¥Æ¥£¥¤¥Ù¥ó¥È¡ÖBlack Hat USA 2024¡×¤Ë¤ª¤¤¤Æ¡¢Aqua Security¤Î¸¦µæ¥Á¡¼¥à¤¬AWS¤Î6¤Ä¤Î¥µ¡¼¥Ó¥¹¤Ë¥¢¥«¥¦¥ó¥È¤Î¾è¤Ã¼è¤ê¤ä¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô¡¢AI¥Ç¡¼¥¿Áàºî¡¢µ¡Ì©¾ðÊóϳ¤¨¤¤¤Ê¤É¤¬µ¯¤³¤ë²ÄǽÀ­¤Î¤¢¤ë½ÅÂç¤ÊÀȼå(¤¼¤¤¤¸¤ã¤¯)À­¤¬¤¢¤Ã¤¿¤Èȯɽ¤·¤Þ¤·¤¿¡£

Cybersecurity News from Black Hat and DefCon| SC Media | SC Media

https://www.scmagazine.com/blackhat

Breaching AWS Accounts Through Shadow Resources - Black Hat USA 2024 | Briefings Schedule

https://blackhat.com/us-24/briefings/schedule/#breaching-aws-accounts-through-shared-resources-39706

Critical vulnerabilities in 6 AWS services disclosed at Black Hat USA | SC Media

https://www.scmagazine.com/news/critical-vulnerabilities-in-6-aws-services-disclosed-at-black-hat-usa



¸¦µæ¥Á¡¼¥à¤Îȯɽ¤Ï¸½ÃÏ»þ´Ö¤Ç2024ǯ8·î7Æü¤Î¸áÁ°Ãæ¡¢¡ÖBreaching AWS Accounts Through Shadow Resources(¥·¥ã¥É¥¦¥ê¥½¡¼¥¹¤ò²ð¤·¤¿AWS¥¢¥«¥¦¥ó¥È¤Î¿¯³²)¡×¤È¤¤¤¦¥¿¥¤¥È¥ë¤Ç¹Ô¤ï¤ì¤Þ¤·¤¿¡£¸¦µæ¥Á¡¼¥à¤Ë¤è¤ë¤È¡¢º£²ó¤ÎÀȼåÀ­¤ÏCloudFormation¡¢Glue¡¢EMR¡¢SageMaker¡¢ServiceCatalog¡¢CodeStar¤È¤¤¤¦¥µ¡¼¥Ó¥¹¤òÍøÍѤ·¤¿ºÝ¤Ë¡¢Í½Â¬²Äǽ¤Ê̿̾¥¹¥­¡¼¥à¤Ë¤ÆS3¥Ð¥±¥Ã¥È¤¬¼«Æ°ºîÀ®¤µ¤ì¤ë¤³¤È¤¬ÌäÂê¤À¤Ã¤¿¤È¤Î¤³¤È¡£

°­°Õ¤Î¤¢¤ë¹¶·â¼Ô¤¬CloudFormation¤Ê¤É¤Î¥µ¡¼¥Ó¥¹¤Ç»ÈÍѤµ¤ì¤ë̾Á°¤Ç¤¢¤é¤«¤¸¤áS3¥Ð¥±¥Ã¥È¤òºîÀ®¤·¤Æ¤ª¤¯¤³¤È¤Ç¡¢¸å¤«¤é¥æ¡¼¥¶¡¼¤¬¥µ¡¼¥Ó¥¹¤Ç»ÈÍѤ¹¤ë¥Õ¥¡¥¤¥ë¤ò¥¢¥Ã¥×¥í¡¼¥É¤¹¤ë¤È¹¶·â¼Ô¤ÎS3¥Ð¥±¥Ã¥È¤ËÇÛÃÖ¤µ¤ì¡¢¹¶·â¼Ô¦¤«¤é¼«Í³¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£Îã¤È¤·¤ÆCloudFormation¤Î¥Æ¥ó¥×¥ì¡¼¥È¥Õ¥¡¥¤¥ë¤ò¥¢¥Ã¥×¥í¡¼¥É¤·¤¿¾ì¹ç¤Ç¤¢¤ì¤Ð¡¢¹¶·â¼Ô¤Ï¥Æ¥ó¥×¥ì¡¼¥È¥Õ¥¡¥¤¥ë¤ËÊݸ¤µ¤ì¤Æ¤¤¤ëµ¡Ì©¾ðÊó¤òÅð¤á¤ë¤À¤±¤Ç¤Ê¤¯¡¢¥Æ¥ó¥×¥ì¡¼¥È¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤Æ¥Ð¥Ã¥¯¥É¥¢¤òÁÞÆþ¤¹¤ë¤³¤È¤â²Äǽ¤Ç¤·¤¿¡£



¸¦µæ¥Á¡¼¥à¤Ï¡¢S3¥Ð¥±¥Ã¥È¤Î¼«Æ°ºîÀ®¤Ë¤ª¤¤¤ÆAWS¥¢¥«¥¦¥ó¥ÈID¤ä¥¢¥«¥¦¥ó¥È¤Ç¶¦Ä̤Υϥ工夬»ÈÍѤµ¤ì¤ëÅÀ¤òƧ¤Þ¤¨¡¢¤³¤¦¤·¤¿¼±Ê̻ҤòÈëÌ©¤Ë¤¹¤ë¤³¤È¤Î½ÅÍ×À­¤òÁʤ¨¤Æ¤¤¤Þ¤¹¡£¤Þ¤¿¡¢º£²ó¤ÎÀȼåÀ­¤¬ÍøÍѤµ¤ì¤¿¾ì¹ç¤Ë¥¢¥«¥¦¥ó¥È¤¬¾è¤Ã¼è¤é¤ì¤ë²ÄǽÀ­¤ÏS3¥Ð¥±¥Ã¥È¤ò»ÈÍѤ·¤¿¥æ¡¼¥¶¡¼¤Î¸¢¸Â¥ì¥Ù¥ë¤Ë°Í¸¤·¤Æ¤¤¤¿¤¿¤á¡¢¥æ¡¼¥¶¡¼¤Ë¥í¡¼¥ë¤ò³ä¤êÅö¤Æ¤ëºÝ¤Ë¸¢¸Â¤òºÇ¾®¤Ë¤¹¤ë¤³¤È¤â½ÅÍפǤ¹¡£

ÀȼåÀ­¤Ï2024ǯ2·î¤ËAWS¥»¥­¥å¥ê¥Æ¥£¥Á¡¼¥à¤ËÊó¹ð¤µ¤ì¡¢2024ǯ6·î¤Þ¤Ç¤ËÁ´¤Æ¤ÎÀȼåÀ­¤¬½¤Àµ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£AWS¤Ï¤³¤Îȯɽ¤ËÂФ·¡¢¡Ö¤¹¤Ç¤ËÌäÂê¤Ï½¤ÀµºÑ¤ß¤Ç¡¢Á´¤Æ¤Î¥µ¡¼¥Ó¥¹¤ÏÁÛÄê¤É¤ª¤ê¤Ëưºî¤·¤Æ¤ª¤ê¡¢¥æ¡¼¥¶¡¼Â¦¤Ç¤ÎÂбþ¤ÏÉÔÍפǤ¹¡×¤È¥³¥á¥ó¥È¤·¤Þ¤·¤¿¡£