Rhino Security Labs

Technical Blog

CVE-2025-0693: AWS IAM User Enumeration

Nate Wilson
February 11, 2025

Username enumeration vulnerabilities can allow attackers to identify valid users, which is the first step in many attacks.  During a recent pentest, we discovered two username enumeration vulnerabilities in the AWS Web Console. These…

CVE-2024-46506: Unauthenticated RCE in NetAlertx

CVE-2024-46507: Yeti Platform
Server-Side Template Injection (SSTI)

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

John De Armas

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, sqs_flag_shop. where you will attempt to move through an AWS…