WEBINAR

The Evolving State of Secrets in Public Cloud Images

Available On-Demand

Public VM images can be a hidden source of credential exposure but how does this risk vary across cloud providers? In this session, security researchers Eduard Agavriloae and Matei Josephs will join Joe Leon from Truffle Security to discuss findings from CloudQuarry, a multi-cloud investigation into secrets exposure across AWS, Azure, and GCP.

Using TruffleHog, they scanned tens of thousands of public images and what they found (and didn’t find) might surprise you!

In this webinar, attendees will learn:

  • Key differences in secret exposure across AWS, Azure, and GCP public images

  • How automation and TruffleHog enable large-scale cloud image scanning

  • Why GCP’s strict marketplace policies appear to eliminate secret leakage

  • Practical takeaways to help prevent secret exposure in your cloud environments