Itdaily - Palo Alto Networks warns of ‘bucket hijacking’ in the cloud

Palo Alto Networks warns of ‘bucket hijacking’ in the cloud

Palo Alto Networks

Bucket hijacking, or the interception of buckets via the cloud, is a major threat according to Palo Alto Networks.

Unit 42, Palo Alto Networks’ research team, is warning of ‘bucket hijacking’. In this process, attackers re-register deleted cloud storage locations (buckets) to intercept sensitive data that is still being sent to the original location.

Deleted cloud storage locations pose a risk if applications or data streams are still sending data to those locations. An attacker can re-register the vacated name and thus gain access to sensitive information. This problem occurs with major cloud providers such as Google Cloud, AWS and Microsoft Azure.

Reusing bucket names

The technique works thanks to the unique naming of storage locations within a cloud environment. Because bucket names are globally unique, an attacker can recreate a deleted bucket under their own account and redirect data streams.

Bucket hijacking can cause logs, backups, and configuration files to leak. Unit 42 advises organizations to limit deletion rights for cloud storage to a small group of administrators. Additionally, it is crucial to map out all dependencies and data streams before deleting buckets.

Effective cloud security requires not only protecting active workloads, but also carefully managing and phasing out cloud resources. Monitoring and alerts for the deletion of storage locations are essential to prevent data leaks.