# Nabaya Solutions > Your Trusted Partner in Cybersecurity & Compliance in Maryland, Virginia and DC ## Posts - [CMMC Phase II Is Suspended. Your Cybersecurity Obligations Are Not.](https://nabayasolutions.com/cmmc-phase-ii-is-suspended-your-cybersecurity-obligations-are-not/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [BREACH & BEYOND, CLOUD SECURITY](https://nabayasolutions.com/https-nabayasolutions-com-cloud-security-misconfiguration/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Why most AI strategies fail before they start](https://nabayasolutions.com/why-most-ai-strategies-fail-before-they-start/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [How to Protect AI Systems from Adversarial Attacks](https://nabayasolutions.com/https-nabayasolutions-com-how-to-protect-ai-systems-from-adversarial-attacks/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [CMMC Compliance Cost for Small Business: 2026 Budget Guide](https://nabayasolutions.com/cmmc-compliance-cost-small-business/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [How to run a security assessment that actually finds your blind spots](https://nabayasolutions.com/security-assessment-blind-spots/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Why Governance, Risk, and Compliance Are the Foundation of a Secure, Resilient Organization By NABAYA Solutions Cybersecurity & Compliance Experts, Laurel, MD, VA, DC](https://nabayasolutions.com/governance-risk-and-compliance/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] ## Pages - [Thank You](https://nabayasolutions.com/thank-you/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Data Analytics](https://nabayasolutions.com/data-analytics/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Software Development](https://nabayasolutions.com/software-development/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Managed & Advisory Services](https://nabayasolutions.com/managed-advisory-services/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [AI Security & Responsible AI](https://nabayasolutions.com/ai-security-responsible-ai/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Cloud Security Services](https://nabayasolutions.com/cloud-security-services/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Governance, Risk & Compliance (GRC)](https://nabayasolutions.com/cybersecurity-compliance-services/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Cybersecurity Services](https://nabayasolutions.com/cybersecurity-services/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Terms & Conditions](https://nabayasolutions.com/terms-conditions/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Contact Us](https://nabayasolutions.com/contact-us/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Careers](https://nabayasolutions.com/cybersecurity-careers/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Services](https://nabayasolutions.com/services/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [About Us](https://nabayasolutions.com/about-us/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Home](https://nabayasolutions.com/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] - [Privacy Policy](https://nabayasolutions.com/privacy-policy/): Cloud misconfiguration: the breach vector hiding in plain sight   Why the #1 cause of cloud breaches isn’t sophisticated hacking; it’s configuration drift. And why your current tooling is only catching part of it. 7 min read · Cloud Security · Analysis In 2019, a misconfigured AWS WAF allowed a Capital One attacker to exploit a server-side request forgery vulnerability and retrieve credentials from the EC2 instance metadata service. The result: 100 million customer records exposed. The attacker did not use a zero-day. There was no nation-state tooling involved. The environment simply wasn’t configured the way it should have been, and […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/nabayasolutions.com/mcp) [comment]: # (Generated by Hostinger Tools Plugin)