Compute Instance with Default Service Account
The Compute Engine default service account is created with the primitive editor role within the project scope. These roles are...
The Compute Engine default service account is created with the primitive editor role within the project scope. These roles are...
AWS lambda function {AwsLambdaFunction} does not follow the principle of least privilege, and shares its IAM role with another function.
Orca has detected that the role {AwsIamRole} was granted full administrative privileges on the account. These privileges grant them the...
The snapshot {AwsEc2EbsSnapshot} is not encrypted.
In the storage account creation process, there are three connectivity methods: Public for all networks, Public for specified networks or...
The API server of {GcpGkeCluster} is publicly accessible from anywhere on the internet. This leaves the Kubernetes API server exposed...
It was detected that the read/write autoscaling of DynamoDB table ({AwsDynamodbTable}) is disabled. Amazon DynamoDB auto scaling uses the AWS...
API Security has risen to the top of the priorities list for CISOs and security teams. As misconfigured APIs have...
Life at Orca Security revolves around the Pod - the people who have joined Orca’s mission to make the cloud...