SSRF to Cloud Metadata: The Attack Behind Capital One and How to Stop It
How SSRF turns one forged request into cloud-wide credential theft — the Capital One chain, IMDSv2, and the controls that actually block it.
How SSRF turns one forged request into cloud-wide credential theft — the Capital One chain, IMDSv2, and the controls that actually block it.
Toyota left one access key on GitHub for five years. This is the full chain: where cloud secrets leak, how attackers turn a found key into root, and the architecture that survives a leak they cannot prevent.
Your IAM system answers 'who has access' — AI agents ask 'what will this identity do next.' The authority gap, three real attack scenarios, and a four-layer framework to close it.