Seth Art's Avatar

Seth Art

@sethsec.bsky.social

Security Research and Advocacy @ Datadog. Former Principal and Cloud Penetration Testing lead @BishopFox. I like to build, break, learn, and share. 
CloudFox, CloudFoxable, BadPods, IAM Vulnerable

602 Followers  |  112 Following  |  9 Posts  |  Joined: 10.09.2023  |  1.6712

Latest posts by sethsec.bsky.social on Bluesky

Preview
Preparing for Hacker Summer Camp and a new cloud image investigator | Datadog Security Labs This month’s digest covers Hacker Summer Camp prep, a new cloud image investigator, and supply-chain vulnerabilities associated with the Open VSX Registry.

The July edition of the Datadog Security Digest is out!

securitylabs.datadoghq.com/newsletters/...

• Cloud image investigator by @sethsec.bsky.social
• Our top picks for Black Hat / DEF CON
• A benchmark for LLM coding accuracy and security
• Malicious Homebrew installation campaign
.. and more

31.07.2025 21:00 — 👍 5    🔁 2    💬 0    📌 0
Post image

fwd:cloudsec is around the corner! Don't miss these 3 talks from Datadog researchers Seth Sec, Katie Knowles, Greg Foss, and Anthony Randazzo.

fwdcloudsec.org/conference/n...

@sethsec.bsky.social
@siigil.bsky.social
@gregfoss.com

27.06.2025 21:02 — 👍 4    🔁 2    💬 0    📌 0
Preview
The whoAMI name confusion attack, modern phishing tactics, and K8s network security fundamentals | Datadog Security Labs This February edition of the Datadog Security Digest dives into the

The February edition of the Datadog Security Digest is out!

securitylabs.datadoghq.com/newsletters/...

featuring @sethsec.bsky.social, @mccune.org.uk, @karimscloud.bsky.social, @jcfarris.bsky.social, and more

27.02.2025 16:32 — 👍 5    🔁 2    💬 0    📌 0
Post image

The Datadog Security Digest is a monthly, practitioner-focused newsletter.

Don't miss our February edition going live tomorrow!

securitylabs.datadoghq.com/newsletters/...

26.02.2025 11:55 — 👍 5    🔁 4    💬 0    📌 0
Preview
whoAMI attacks give hackers code execution on Amazon EC2 instances Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name.

whoAMI attacks give hackers code execution on Amazon EC2 instances

13.02.2025 23:59 — 👍 14    🔁 9    💬 0    📌 1

When I first started reading this I though,t “is this really news, this issue has been around for years…” but then it gets interesting - kudos to the researchers on this one!

12.02.2025 20:25 — 👍 5    🔁 1    💬 0    📌 0
Preview
whoAMI: A cloud image name confusion attack | Datadog Security Labs Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.

Need to hack thousands of AWS customers? What about on internal AWS systems? Datadog Security Research found that a number of tools, including one published by AWS, are susceptible to name confusion attacks, leading to RCE in vulnerable environments!

securitylabs.datadoghq.com/articles/who...

12.02.2025 17:19 — 👍 19    🔁 6    💬 1    📌 0
Preview
whoAMI: A cloud image name confusion attack | Datadog Security Labs Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.

I’m excited to share our research on the “whoAMI” attack. We discovered that AWS customers pulling AMI IDs insecurely could accidentally use malicious images instead of the legitimate ones— leading to remote code execution.

securitylabs.datadoghq.com/articles/who...

12.02.2025 16:56 — 👍 12    🔁 3    💬 1    📌 1
Preview
whoAMI: A cloud image name confusion attack | Datadog Security Labs Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.

We discovered a pattern in the way many projects retrieve Amazon Machine Images (AMIs), allowing attackers to publish AMIs with specially crafted names and gain code execution within vulnerable accounts.

securitylabs.datadoghq.com/articles/who...

by @sethsec.bsky.social

12.02.2025 15:29 — 👍 8    🔁 5    💬 1    📌 1
Preview
🧙 Why I’m Joining Wiz I’m joining the leading cloud security startup, hoping to “work for the Security Industry, at Wiz.”

New year, new job!

I've joined the amazing @wiz_io research team

My goal is the "work for the security industry, at Wiz"

I wrote a blog post explaining why, and what that means:
ramimac.me/joining-wiz

28.01.2025 15:01 — 👍 33    🔁 4    💬 3    📌 0
Preview
Datadog threat roundup: top insights for Q4 2024 | Datadog Security Labs Threat insights from Datadog Security Labs for Q4 2024.

Threat insights from Datadog Security Labs for Q4 2024

securitylabs.datadoghq.com/articles/202...

28.01.2025 15:14 — 👍 5    🔁 5    💬 0    📌 0

I'm not saying I'm an AWS expert… but I am saying I finally tracked down the random AWS account charging me small amounts every month and closed it.

02.01.2025 20:23 — 👍 57    🔁 4    💬 3    📌 2
weird interaction with a student this week. they kept coming up with weird "facts" ("greek is actually a combination of four other languages") that left me baffled. i said let's look this stuff up together, and they said ok, i'll open a search bar, and they opened... ch*tgpt

weird interaction with a student this week. they kept coming up with weird "facts" ("greek is actually a combination of four other languages") that left me baffled. i said let's look this stuff up together, and they said ok, i'll open a search bar, and they opened... ch*tgpt

and i was like "this is not a search bar" and they were like "yes it is, you can search for anything in here"

the thing that made me feel crazy is like. every kid that's using this as a browser is getting new BESPOKE false "facts." this isn't "a widespread misconception about X that stems from how it's taught in schools." each individual kid is now hooked into a Nonsense Machine

with the "widespread misconception about X" you can start at a baseline. like, ok, in tenth grade we all talk about X thing from history, and that leaves us with some misguided concepts about X, but we can correct that as students get broader understandings of the world

but with this, each child is getting UNIQUE wrong facts they are SURE are correct... because they did what we told them to do! they "looked it up"! they got it from somewhere! it's not a kid making up a belief on hearsay and assumption... it's something they think they LEARNED

and i was like "this is not a search bar" and they were like "yes it is, you can search for anything in here" the thing that made me feel crazy is like. every kid that's using this as a browser is getting new BESPOKE false "facts." this isn't "a widespread misconception about X that stems from how it's taught in schools." each individual kid is now hooked into a Nonsense Machine with the "widespread misconception about X" you can start at a baseline. like, ok, in tenth grade we all talk about X thing from history, and that leaves us with some misguided concepts about X, but we can correct that as students get broader understandings of the world but with this, each child is getting UNIQUE wrong facts they are SURE are correct... because they did what we told them to do! they "looked it up"! they got it from somewhere! it's not a kid making up a belief on hearsay and assumption... it's something they think they LEARNED

this kid was extremely combative with me, and i understood why. i was sitting in front of him and telling him that the internet, a computer, technology, all these supposedly authoritative things... were wrong. and that i, one person, was right. he basically *couldn't* believe me.

8

135

3.8K

97K

...

stillorangecrushed @stilloranged. 7h

he decided that i was simply a teacher who'd made a mistake. he could check it, after all! he could look it up! he could find the REAL facts. i obviously hadn't done that, i was just an adult who'd decided i was smarter than him. hence the defensiveness. like i said: i understood

5

760

3.2K

82K

stillorangecrushed @stilloranged. 7h

...

it was so fucking rough. i did my best, but i am one person trying to work against a campaign of misinformation so vast that it fucking terrifies me. this kid is being set up for a life lived entirely inside the hall of mirrors

this kid was extremely combative with me, and i understood why. i was sitting in front of him and telling him that the internet, a computer, technology, all these supposedly authoritative things... were wrong. and that i, one person, was right. he basically *couldn't* believe me. 8 135 3.8K 97K ... stillorangecrushed @stilloranged. 7h he decided that i was simply a teacher who'd made a mistake. he could check it, after all! he could look it up! he could find the REAL facts. i obviously hadn't done that, i was just an adult who'd decided i was smarter than him. hence the defensiveness. like i said: i understood 5 760 3.2K 82K stillorangecrushed @stilloranged. 7h ... it was so fucking rough. i did my best, but i am one person trying to work against a campaign of misinformation so vast that it fucking terrifies me. this kid is being set up for a life lived entirely inside the hall of mirrors

Well this is grim

06.07.2024 22:15 — 👍 13531    🔁 5375    💬 384    📌 1121

Well now that I got this far down that thread I need to know also.

10.12.2024 04:20 — 👍 1    🔁 0    💬 0    📌 0

Plenty of additional information about the compromise of OpenWRT’s online build service, involving command-injection and hash bypass 🧠

08.12.2024 21:32 — 👍 10    🔁 1    💬 0    📌 2
Preview
Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages | Datadog Security Labs Release of Supply-Chain Firewall, an open source tool for preventing the installation of malicious PyPI and npm packages

Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages

securitylabs.datadoghq.com/articles/int... by @ikretz.bsky.social

New open-source tool designed to transparently block known malicious PyPI and npm packages.

github.com/DataDog/supp...

06.12.2024 12:33 — 👍 10    🔁 6    💬 1    📌 0
Preview
GitHub - DataDog/supply-chain-firewall: A tool for preventing the installation of malicious PyPI and npm packages :fire: A tool for preventing the installation of malicious PyPI and npm packages :fire: - DataDog/supply-chain-firewall

Another cool little tool from Datadog Labs. #cybersecurity


https://github.com/DataDog/supply-chain-firewall

06.12.2024 12:43 — 👍 5    🔁 2    💬 0    📌 0

We're now officially on Bluesky!

Expect:

➔ New articles on Security Labs about cloud, container and application security
➔ OSS projects for cloud security practioners
➔ Conference talks at community conferences

See also our starter pack bsky.app/starter-pack... with our authors and researchers!

03.12.2024 14:30 — 👍 20    🔁 10    💬 2    📌 2
Preview
Awseye - See Inside AWS Accounts Awseye tracks publicly accessible AWS data to help identify and secure known and exposed AWS resources. Empowering defenders with open-source intelligence.

The self described “Shodan of AWS” is now live! This is an amazing project from Daniel Grzelak that helps democratize cloud resource enumeration for the masses. Very excited about this!
awseye.com

26.11.2024 02:31 — 👍 73    🔁 35    💬 2    📌 3
Preview
Modern Red Teaming: macOS, K8s, and Cloud - RTV 24 (Public) Modern Red Teaming: macOS, K8s, and Cloud Carnal0wnage int0x80

DualCore and I spoke at the Red Team Village this year. Here are the slides. QR code with link to gist with all the reference links on last page. Unfortunately it wasn't recorded.

docs.google.com/presentation...

#redteam #purpleteam #redteamvillage

24.11.2024 19:35 — 👍 34    🔁 18    💬 0    📌 0

- Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview by Ian Kretz & Sebastián Obregoso
- Escalating from reader to contributor in Azure API Management by Christian August Holm Hansen
- IAM Condition operators explained by Cloud Copilot

and more...
🧵(3/3)

22.11.2024 19:40 — 👍 0    🔁 0    💬 0    📌 0

- Exploiting Fortune 500 through hidden supply chain links by Roni Carta
- Cloud guardrails by Mark Andersen, William Bengtson, Adam Cotenoff, ☁️ Houston Hopkins ☁️, Nicholas Siow, and Travis McPeak
🧵(2/3)

22.11.2024 19:40 — 👍 0    🔁 0    💬 1    📌 0
Preview
Google Cloud Trends, DPRK npm Threats, & Privilege Escalation Walkthroughs | Datadog Security Labs In the November edition, read about Google Cloud Trends, DPRK npm Threats, & Privilege Escalation Walkthroughs, and more.

The November edition of the Datadog Security Digest is live!
securitylabs.datadoghq.com/newsletters/...

Featuring:
- Exploring Google Cloud default service accounts: deep dive and real-world adoption trends by Christophe Tafani-Dereeper
🧵(1/3)

22.11.2024 19:40 — 👍 2    🔁 0    💬 1    📌 0
Kubernetes Security Fundamentals: Authentication - Part 2
YouTube video by Datadog Kubernetes Security Fundamentals: Authentication - Part 2

Latest video in my Kubernetes Security Fundamentals series is out. Looking at some lesser known bits of Kubernetes authentication, bootstrap and static tokens!

youtu.be/1QNKj1rW5H0?...

21.11.2024 10:00 — 👍 21    🔁 3    💬 0    📌 0
Preview
Cloud Security Join the conversation

Now as a starter pack: go.bsky.app/5HpWAcM

18.11.2024 15:40 — 👍 7    🔁 1    💬 1    📌 1
Post image

We made it easy for you to find us!
The Red Siege Starter Pack is now up!
Find the team here - go.bsky.app/ERU72bD

#infosec #cybersecurity

19.11.2024 15:37 — 👍 9    🔁 5    💬 0    📌 0

That word is the worst!

20.11.2024 17:23 — 👍 1    🔁 0    💬 1    📌 0

This is such a good story about how "gotofail" started as a drunken brag in a bar and ended up being disclosed to Apple via a burner phone. It was Ryan all along, finally taking credit after all these years!

18.11.2024 10:53 — 👍 14    🔁 5    💬 1    📌 0

I created a list of Cloud Security folks on here. bsky.app/profile/scot...

18.11.2024 00:57 — 👍 44    🔁 9    💬 4    📌 1

Backdated posts are possible, and given what the API exposes, they are indistinguishable from normal posts 🤔

16.11.2024 13:00 — 👍 4    🔁 2    💬 2    📌 1

@sethsec is following 20 prominent accounts