
For a few years now, the use of managed services in cloud environments has been growing and is tending to become the norm. Last November, we decided to start research work on the security issues related to these environments, beginning with the Kubernetes product deployed at the largest cloud providers.
Our first investigations led us to discover and publish a core Kubernetes CVE, a vulnerability we were then able to exploit as part of Bug Bounty programs.
The talk will focus mainly on Azure, where we were able to access internal data and win one of the program's biggest rewards.
Through this 6-month experience, our aim is to share with the infosec community the technical results of our investigations, but also to give a feedback account of what the life of a Bug Bounty Hunter is like.
Write-up technique déjà existant : https://medium.com/@BreizhZeroDayHunters/when-its-not-only-about-a-kubernetes-cve-8f6b448eafa8
Brice Augras a.k.a Zax
Passionate about cybersecurity for over 10 years, I take a mischievous pleasure in racking my brain to push back the limits of "standard" operation.
Achievement, the need for constant learning and personal pride are the feelings of accomplishment I get when I overcome a technical challenge in the world of Hacking.
I apply the #TryHarder and #RTFM policy to keep progressing, get out of my technical comfort zone and farm knowledge.
Cybersecurity manager by day in an SME and Bug Bounty Hunter by night and at weekends, I'm lucky to have made a lifelong passion my everyday job…
Christophe Hauquiert aka Hach
A long-time computing enthusiast and self-taught, I fell into it very young, starting by designing and administering infrastructures to host game servers.
I then discovered the field of computer security and hacking, and I was immediately hooked. Since then I've enjoyed learning and continuing to develop my skills, always with passion, in these two areas.
Today I'm a Kubernetes architect at a telecom company by day, and by night and at weekends I'm an entrepreneur and bug bounty hunter.

