Cyber Security

SAPwned Vulnerability Attack Let Hackers Gain Control to Users Cloud Environments

Multiple vulnerabilities in SAP AI Core had been identified, giving malicious actors access to customer data and the ability to take control of the service.

With SAP AI Core, users may leverage the company’s extensive cloud resources to create, train, and operate AI services in a scalable and controlled manner. 

The customer’s code operates inside SAP’s common environment, much like other cloud providers (and AI infrastructure suppliers) do. This presents a risk of cross-tenant access. 

“ The vulnerabilities we found could have allowed attackers to access customers’ data and contaminate internal artifacts – spreading to related services and other customers’ environments”, Wiz Research Team shared with Cyber Security News.

Protect Your Business Emails From Spoofing, Phishing & BEC with AI-Powered Security | Free Demo

Findings Into SAP AI Core

Research on SAP AI Core, dubbed “SAPwned,” began by utilizing SAP’s infrastructure to conduct legitimate AI training techniques. 

Researchers could move laterally and take over the service by executing arbitrary code.

They obtained credentials to customers’ cloud environments, including AWS, Azure, SAP HANA Cloud, and more, as well as access to their private data.

Attack Phases

The primary cause of these issues was attackers’ ability to execute malicious AI models and training procedures, which are effectively code. 

Vulnerabilities Detected

Despite the fact that SAP’s admission controller eliminated every risky security setting, experts discovered two intriguing configurations that the admission controller overlooked. 

An access token to the cluster’s centralized Istiod server was obtained, granting access to the Istio configuration. Finally using the power of 1337 to bypass the network restrictions.

After requesting to inspect Loki’s configuration via the /config path, the complete setup, including the AWS secrets that Loki needed to access, was sent back via the API.

Moreover, massive volumes of AI data, including code and training datasets, sorted by customer ID have been revealed by AWS Elastic File System (EFS) instances.

The internal Docker Registry and Artifactory are compromised via an unauthenticated Helm server. 

Here, an attacker might examine internal builds and images using the read access provided by these secrets, potentially capturing client data and commercial secrets.

Also, an attacker could undertake a supply-chain attack against SAP AI Core services by compromising builds and images by leveraging the write access granted by the secrets. 

Finally, an unauthorized Helm server was found to be infecting the K8s cluster, revealing Google access tokens and confidential client information.

The SAP access key increases the scope of a possible supply-chain attack by granting read and write access. 

As stated on their website, SAP has recognized that all vulnerabilities have been disclosed to and addressed by their security team. There was no compromise of customer information. 

The attack’s impact might have been reduced by hardening the internal services, and the severity might have gone down from a full-service takeover to minor security events.

Additionally, suitable barriers must be in place to guarantee that untrusted code is kept apart from other tenants and internal resources. 

Join our free webinar to learn about combating slow DDoS attacks, a major threat today.

Cyber Advisory

CISO Advisory is a Team of Security Experts Covering Various Cybersecurity Research and Technical Write-ups.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago