How I hacked a cloud production environment with external Terraform manipulation
Uri Aronovici
BSides NYC 2024 · Day 1 · Tech - Red
In his compelling BSides NYC talk, "How I hacked a cloud production environment with external Terraform manipulation," Uri Aronovici, CTO and co-founder of Zest, unveiled critical security risks inherent in the widespread use of Terraform providers and modules. Aronovici, drawing from over a decade of experience in vulnerability management and cloud security, specializing in both offensive and defensive strategies, highlighted how these foundational infrastructure-as-code components can become vectors for significant cloud environment compromise. His presentation served as a stark reminder that even seemingly innocuous or officially sanctioned tools can harbor vulnerabilities exploitable for privilege escalation, data exfiltration, and complete system control.
AI review
Competent IaC supply chain talk that covers real ground — provider vuln stats across registry tiers, a credible real-world Vault provider exploitation story, and a practical malicious module demo — but stops short of being a must-see. The research is sound but not deeply novel, and the defensive section reads like a compliance checklist more than hard-won operational insight.