Pwned Labs Blog


The latest techniques in hacking and defending

GCP Privilege Escalation: How Attackers Escalate in Google Cloud IAM

Privilege escalation is where most real cloud compromises are won or lost. In Google Cloud, an attacker rarely starts...

Cloud Pentesting Methodology: From Reconnaissance to Privilege Escalation Across AWS, Azure, and GCP

Why Cloud Pentesting Requires a Different Approach Traditional penetration testing methodology (scan, enumerate,...

Attacking Kubernetes in the Cloud: Container Escape to Cluster Admin

Why Kubernetes Is the Next Frontier for Cloud Red Teams Kubernetes has become a primary pivot point in cloud breaches:...

CI/CD to Shell: The GitLab Exploitation Path

CI/CD systems are everywhere now, a core part of the DevOps ecosystem. CI/CD combines continuous integration and...

Climbing the Azure RBAC Ladder

Join us in this new blog post as we explore the various methods that threat actors commonly use to move laterally and...

Beginner's Guide to hunting for AWS IAM Privilege Escalations with Pacu

Join us as we get started with using Pacu - an AWS exploitation framework created by Rhino Security Labs that is...

Your security training ground


Experience, real-world, byte-sized cloud security labs for training cyber warriors. From beginners to pros, our engaging platform allows you to secure your defenses, ignite your career and stay ahead of threats.