Snowflake attacks - what happened, and 6 mitigations to prevent it happening to you

  Рет қаралды 486

Steve Townsley

Steve Townsley

Күн бұрын

In this video I discuss the recent attacks against Snowflake cloud data instances. These attacks aren't compromising Snowflake directly, but using legitimate credentials. These credentials are then being used against Snowflake customer environments.
In this video I talk about what happened, why this is interesting, and suggest 6 mitigations.
Mandiant blog: cloud.google.com/blog/topics/...
Okta compromise: sec.okta.com/articles/2023/11...
Snowflake advice: community.snowflake.com/s/que...
00:00 Introduction.
01:05 What happened?
01:59 The history.
04:41 Why is this interesting?
08:17 How can we defend against this?
17:25 Outro.
#informationsecurity #cybersecurity #snowflake

Пікірлер: 13
@theGaryRuddell
@theGaryRuddell 13 күн бұрын
Great briefing on Snowflake! And thanks for the shoutout!
@Steve_Townsley
@Steve_Townsley 13 күн бұрын
Any time!
@EimhinONeill
@EimhinONeill 8 күн бұрын
Love this Steve. So much noise and rumour in the media about the breach but to finally get some clarity is fantastic!
@Steve_Townsley
@Steve_Townsley 8 күн бұрын
Thanks for that lovely feedback! Yes it’s got quotes noisy about what happened in these attacks. Glad you found the video useful 🙂
@alexwloch1088
@alexwloch1088 13 күн бұрын
Fantastic video sir as always. Bring on the next episode.
@Steve_Townsley
@Steve_Townsley 13 күн бұрын
Thanks very much good sir!
@stephenrandles9248
@stephenrandles9248 13 күн бұрын
Thanks for the video Steve, I really liked your approach to cloud security with multiple layers of defence and awareness of services being key. Snowflake does bring into focus the weakness of service accounts and capabilities to use info stealers. 🔐
@Steve_Townsley
@Steve_Townsley 13 күн бұрын
Thanks! I glad you enjoyed the video. Definitely underscores the benefits of defence in depth 🙂
@UBA_NOOB
@UBA_NOOB 13 күн бұрын
Another great video Steve. What I found really interesting was your advice on password hygiene reversing the current NCSC guidance regarding password refresh. Do you think infostealers will make the likes of NCSC update their advice?
@Steve_Townsley
@Steve_Townsley 13 күн бұрын
Thanks! I think the National Cyber Security Centre advice on passwords is already excellent. But, if infostealers increase in popularity and we’re not rotating passwords then we’re going to have a problem. I definitely think that passwordless can help here, and I’m not sure what advice exists for high privilege service accounts. Those feel like credentials that should be rotated. Ultimately we need to also think about how we protect passwords.
@tomtech1537
@tomtech1537 10 күн бұрын
Similar to my other point but you raise it more specifically. Entra Conditional Access Policies won't prevent token teleportation; initial authorization will check the policy but once a user has that token it can be [stolen and] used everywhere without issue, unless continuous evaluation is enabled.
@Steve_Townsley
@Steve_Townsley 10 күн бұрын
That's a good point and one which I think is often overlooked. All the CAP checks (apart from CAE as you say) is at point of authorisation!
"I Hate Agile!" | Allen Holub On Why He Thinks Agile And Scrum Are Broken
8:33
How YouTube Beat Netflix And Disney In The Streaming Wars
13:56
버블티로 체감되는 요즘 물가
00:16
진영민yeongmin
Рет қаралды 64 МЛН
The joker's house has been invaded by a pseudo-human#joker #shorts
00:39
Untitled Joker
Рет қаралды 6 МЛН
Haha😂 Power💪 #trending #funny #viral #shorts
00:18
Reaction Station TV
Рет қаралды 14 МЛН
Василиса наняла личного массажиста 😂 #shorts
00:22
Денис Кукояка
Рет қаралды 9 МЛН
What Does an LLM-Powered Threat Intelligence Program Look Like?
40:11
EDR, MDR & XDR Explained
10:33
Pro Tech Show
Рет қаралды 29 М.
Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
17:34
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 559 М.
Infostealer malware is out to get you
9:07
Gary Ruddell
Рет қаралды 2,1 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,7 МЛН
2024 Cybersecurity Trends
7:57
IBM Technology
Рет қаралды 155 М.
Cybersecurity Vs. Cloud Computing VS IT - Which is better for career & pay?
8:53
Nicole Enesse - Cybersecurity For Mere Mortals
Рет қаралды 69 М.
DHH - Ruby on Rails, 37signals, and the future of web development
1:09:57
Неразрушаемый смартфон
1:00
Status
Рет қаралды 1,7 МЛН
Gizli Apple Watch Özelliği😱
0:14
Safak Novruz
Рет қаралды 3,7 МЛН
Hisense Official Flagship Store Hisense is the champion What is going on?
0:11
Special Effects Funny 44
Рет қаралды 1,8 МЛН
После ввода кода - протирайте панель
0:18