Rhino Security Labs

Technical Blog

Using AWS Account ID’s for IAM User Enumeration

Benjamin Caudill

In our AWS IAM post from last week, we highlighted a technique that penetration testers can use to automate the process of enumerating the IAM roles of other AWS accounts. As long as the attacker knows the victim’s AWS account ID,…

S&P Considering Cybersecurity Risk in Bank Credit Ratings

Benjamin Caudill

Some of most powerful financial regulators in the United States have taken a stand on cybersecurity, telling American banks to reduce their cybersecurity risk – or pay up.
Credit rating firm Standard and Poor’s recently announced…