
ISC StormCast for Friday, March 4th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
Gogles Cloud Armor - An Attack Against a Google Cloud Servlet
An attacker would need to trick a user into using a skill that will then speak a particular command, and that command will be executed by the speaker. One suggested version of the attack woud essentially just play the audio files on an innonant radio station. The only work around here is to not allow requests greater than eight kilobites.
Play episode from 02:27
Transcript


