No Way Out? C2 Through AWS Data Perimeter via Bedrock-AgentCore - Dan Gansel
This is a corrected version since the original recording had some visual issues. Link to the old version: • No Way Out? C2 Through AWS Data Perimeter ... Speaker: Dan Gansel Dan Gansel is a cloud security specialist with deep expertise in cloud API research, secure cloud solutions and architecture design. Dan has led cloud security research teams and has a track record of uncovering novel attack techniques in cloud environments. As a Security Researcher at Upwind Security, Dan continues to push the boundaries of cloud security, focusing on uncovering blind spots in the services organizations trust the most. Talk: The Data perimeter is the gold standard for cloud-native security boundary in AWS. It combines all available preventive security tools and guardrails. In this talk you will learn about a novel attack technique that exploits AWS Bedrock AgentCore’s identity service to establish a fully functional command and control channel (C2) capable of bypassing data perimeter controls - all while using legitimate capabilities. We will demonstrate how an attacker can use two covert channels hidden in plain sight: data exfiltration and unauthenticated data infiltration. We will demo the complete C2 channel operating end to end - an attacker establishing persistence, issuing commands and exfiltrating sensitive data from an S3 bucket containing user records, all within an enforced data perimeter. We will also walk through CloudTrail signals which will enable defenders to detect this activity and discuss why new AI services demand security assessment before adoption. Recorded at fwd:cloudsec North America 2026 - Bellevue, WA https://fwdcloudsec.org/conference/no...

Discovering New AWS Privilege Escalation Paths with an AI-Driven Workflow - Seth Art

Data Perimeters: Beyond the Marketing - Matt Luttrell

Cyber Threat Intelligence in Europe: Regulation, Automation, and Human Judgement

Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF - S Berkovich

Paying More for Worse Security: An AWS Marketplace Horror Story - Corey Quinn

I Hacked This Temu Router. What I Found Should Be Illegal.

But what is quantum computing? (Grover's Algorithm)

Something is jamming GPS over Europe. Here's what we found

Who Are the Robots? Uncovering AI Agents Identities - Ron Popov & Clément Notin

Trump Preps for 80th Birthday, Threatens to Hit Iran, Knicks Historic Win & Elon Musk Trillionaire!?

Observing Escalation Paths in Kubernetes - William Taylor

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

Artificial Intelligence 🤝 Natural Stupidity - Brandon Sherman

When One Vulnerability Cascades Across Cloud Infrastructure - Albin Vattakattu & Ryan Nolette

Beyond the Checkbox: What Breaks When You Actually Stress-Test Cloud Incident Response - M Harvey

Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns - Shahar Dorfman & Sapir Federovsky

AWS Explained: The Most Important AWS Services To Know

Schrödinger’s Detection: Finding the "Zombie" Rules in Your SIEM - Gowthamaraj

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt

