Pwned Labs Blog


The latest techniques in hacking and defending

Attacking Kubernetes in the Cloud: Container Escape to Cluster Admin

Why Kubernetes Is the Next Frontier for Cloud Red Teams Kubernetes has become a primary pivot point in cloud breaches:...

CI/CD to Shell: The GitLab Exploitation Path

CI/CD systems are everywhere now, a core part of the DevOps ecosystem. CI/CD combines continuous integration and...

Cloud Pentesting Certification: AWS, Azure & GCP

A cloud pentesting certification is worth exactly as much as the skill it proves. The question a hiring manager or a...

Cloud Penetration Testing: A Beginner's Guide

Cloud penetration testing means safely simulating real attacks against a cloud environment to find the weaknesses...

A new S3 namespace - and a new problem

AWS S3 has long suffered from the bucketsquatting problem. Because bucket names lived in a single global namespace,...

Getting started with AWS Security

Many people want to know "how do I get started with AWS security?", and this blog post is for them. The pathway in this...

Meet your ACRTP Bootcamp instructor: Tyler Petty

From building military-grade networks to cloud security guardrails, Tyler's journey into cybersecurity has been...

Meet your MCRTP Bootcamp instructor: Filip Jodoin

We sat down with Filip Jodoin, Penetration Tester and Pwned Labs instructor, to find out more about his cybersecurity...

RansomWhen: The Hidden Risks of AWS KMS in Ransomware Attacks

Disclaimer: The information in this blog post is provided for educational and informational purposes only. We do not...

Defending Against the whoAMI Attack with AWS Declarative Policies

Cloud Security Researcher and Advocate, Seth Art, recently published the blog post whoAMI: A cloud image name confusion...

Your security training ground


Experience, real-world, byte-sized cloud security labs for training cyber warriors. From beginners to pros, our engaging platform allows you to secure your defenses, ignite your career and stay ahead of threats.