445 | Abusing Azure App Service Managed Identity Assignments |
Cloud |
Microsoft (Azure) |
Andy Robbins (@_wald0) |
Bug Bounty | 2023-02-15 | 2023-06-13 |
433 | Disabling ClamAV as an Unprivileged User |
Local Privilege Escalation |
ClamAV |
Arch Cloud Labs (@DLL_Cool_J) |
Bug Bounty | 2023-02-19 | 2023-06-13 |
419 | Taking over “Google Cloud Shell” by utilizing capabilities and Kubelet |
Container escape
RCE
Kubernetes |
NA |
Chen Shiri (@ChenShiri73) |
Bug Bounty | 2023-02-21 | 2023-06-13 |
371 | Gitpod remote code execution 0-day vulnerability via WebSockets |
RCE
Websockets
Cross-Site WebSocket Hijacking (CSWH)
Cloud
Samesite cookie bypass
Account takeover |
Gitpod |
Elliot Ward |
Bug Bounty | 2023-03-01 | 2023-06-13 |
356 | Bypass TCC via iCloud |
TCC bypass
Local Privilege Escalation |
Apple (macOS) |
Wojciech Reguła (@_r3ggi) |
Bug Bounty | 2023-03-04 | 2023-06-13 |
350 | 500$ Bounty in just 5 minutes through Recon!!!! |
AWS misconfiguration
Cloud storage misconfiguration |
NA |
Himanshu Pdy (@himanshu_pdy) |
Bug Bounty | 2023-03-05 | 2023-06-13 |
308 | Microsoft Defender for Cloud Management Port Exposure Confusion |
Cloud
Security misconfiguration |
Microsoft |
Aaron Sawitsky |
Bug Bounty | 2023-03-14 | 2023-06-13 |
278 | Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research |
Cloud
CloudTrail bypass |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-03-20 | 2023-06-13 |
270 | Escalating Privileges with Azure Function Apps |
Privilege escalation
Cloud
Container escape
RCE |
Microsoft (Azure) |
Karl Fosaaen (@kfosaaen) |
Bug Bounty | 2023-03-23 | 2023-06-13 |
267 | Hacking AI: System and Cloud Takeover via MLflow Exploit |
LFI
RFI
RCE |
MLflow |
Dan McInerney (@DanHMcInerney) |
Bug Bounty | 2023-03-25 | 2023-06-13 |
263 | Using an Undocumented Amplify API to Leak AWS Account IDs |
Cloud
Information disclosure |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-03-27 | 2023-06-13 |
256 | I’d TAP That Pass |
Azure AD
Cloud
OAuth |
NA |
Daniel Heinsen (@hotnops) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
255 | BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained |
Account takeover
Azure AD
Cloud
XSS
Privilege escalation |
Microsoft (Bing) |
Hillai Ben-Sasson (@hillai) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
251 | Riding the Azure Service Bus (Relay) into Power Platform |
RCE
Cross-tenant vulnerability
Cloud
Insecure deserialization |
Microsoft (Azure) |
Nick Landers (@monoxgas) |
Bug Bounty | 2023-03-30 | 2023-06-13 |
248 | Super FabriXss: From XSS to an RCE in Azure Service Fabric Explorer by Abusing an Event Tab Cluster Toggle (CVE-2023-23383) |
RCE
XSS
Cloud |
Microsoft (Azure) |
Lidor Ben Shitrit |
Bug Bounty | 2023-03-30 | 2023-06-13 |
236 | Two Minor Cross-Tenant Vulnerabilities in AWS App Runner |
Cross-tenant vulnerability
Cloud |
AWS |
Nick Frichette (@frichette_n) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
210 | From listKeys to Glory: How We Achieved a Subscription Privilege Escalation and RCE by Abusing Azure Storage Account Keys |
Cloud
Privilege escalation |
Microsoft (Azure) |
Roi Nisimi (@) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
182 | #BrokenSesame: Accidental write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services |
Cloud
RCE
Container escape
Kubernetes
Privilege escalation
Lateral movement
Supply chain attack
Cross-tenant vulnerability |
Alibaba |
Ronen Shustin (@ronenshh) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
177 | How I hacked hackers in Voorivex Hunt Event |
Cloudflare bypass
WAF bypass
Account takeover |
NA |
snoopy (@snoopy101101) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
176 | CVE-2022-29844: A Classic Buffer Overflow On The Western Digital My Cloud Pro Series PR4100 |
Buffer Overflow
Memory corruption
RCE |
Western Digital |
Luca Moro (@johncool__) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
171 | GhostToken – Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts |
Cloud
OAuth
Authorization bypass |
Google (GCP) |
Astrix Security (@AstrixSecurity) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
136 | AWS Identity Center (formerly known as AWS SSO): A Guide to Privilege Escalation and Identity and Access Management |
Privilege escalation
Cloud |
AWS |
Jason Kao |
Bug Bounty | 2023-05-01 | 2023-06-13 |
132 | Securing Databricks cluster init scripts |
Privilege escalation
Cloud |
Databricks |
Elia Florio |
Bug Bounty | 2023-05-02 | 2023-06-13 |
131 | Exploiting misconfigured Google Cloud Service Accounts from GitHub Actions |
OpenID Connect
Cloud
CI/CD |
NA |
Revblock (@revbl0ck) |
Bug Bounty | 2023-05-02 | 2023-06-13 |
130 | When you%27re so bored, you start debugging someone else%27s code: bug hunting in a random Cloud-Native project |
SSTI
RCE |
Foreman |
ONSEC.io Research Team |
Bug Bounty | 2023-05-03 | 2023-06-13 |