Tag: domain-specific languages (DSLs)

Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks
News

Cybersecurity Blind Spots in IaC and PaC Tools Expose Cloud Platforms to New Attacks

Researchers in cybersecurity have revealed two novel attack methods that use dedicated, domain-specific languages (DSLs) to compromise cloud platforms and steal data from infrastructure-as-code (IaC) and policy-as-code (PaC) tools such as HashiCorp's Terraform and Styra's Open Policy Agent (OPA). In a technical paper released last week, Tenable senior security researcher Shelly Raban stated that these languages are more secure than ordinary programming languages because they are hardened and have fewer features. More secure does not equate to bulletproof, though. Organizations may enforce policies across cloud-native systems, including microservices, CI/CD pipelines, and Kubernetes, using OPA, a well-liked open-source policy engine read more about Cybersecurity Blind Spots in IaC an...