WEBINAR
The Evolving State of Secrets in Public Cloud Images
Available On-Demand
Public VM images can be a hidden source of credential exposure but how does this risk vary across cloud providers? In this session, security researchers Eduard Agavriloae and Matei Josephs will join Joe Leon from Truffle Security to discuss findings from CloudQuarry, a multi-cloud investigation into secrets exposure across AWS, Azure, and GCP.
Using TruffleHog, they scanned tens of thousands of public images and what they found (and didn’t find) might surprise you!
In this webinar, attendees will learn:
Key differences in secret exposure across AWS, Azure, and GCP public images
How automation and TruffleHog enable large-scale cloud image scanning
Why GCP’s strict marketplace policies appear to eliminate secret leakage
Practical takeaways to help prevent secret exposure in your cloud environments