Nitesh Surana

Nitesh Surana

Sr. Cloud Threat Researcher | Top 100 MSRC Researchers 2023, 2024
About

Nitesh Surana is a Senior Cloud Threat Researcher at Trend Micro with over five years of experience in cybersecurity. He began his career as a SOC analyst in 2019 before transitioning into threat research, where he now focuses on cloud and cloud-native environments, software supply chain attacks, vulnerabilities, threats, and security misconfigurations.

Through coordinated disclosure of vulnerable designs impacting more than 10 Azure services, Nitesh has been recognized among the Top 10 Microsoft Security Researchers in 2024 while working with the Trend Zero Day Initiative. His research on Azure and Microsoft services, as well as investigations into cloud threat actor credential leaks, has been presented at conferences including Black Hat USA and Asia, Blue Hat USA, FIRSTCON, HackInTheBox, HackInParis, Virus Bulletin, Nullcon, Vulncon and c0c0n.

Outside of keyboards, he enjoys metal music and spending time in the Himalayas.

Links
Hacking Archives of India · LinkedIn · X · Mastodon · Bluesky · YouTube
Blogs
DateBlog
2025-10-08A Cascade of Insecure Architectures: Axis Plugin Design Flaw Expose Select Autodesk Revit Users to Supply Chain Risk
2025-04-15ZDI-23-1527 and ZDI-23-1528: The Potential Impact of Overly Permissive SAS Tokens on PC Manager Supply Chains
2024-10-16Fake LockBit, Real Damage: Ransomware Samples Abuse Amazon S3 to Steal Data
2024-07-25The Mirage of AI Programming: Hallucinations and Code Integrity
2024-07-11Leaky Labels: Bypassing Traefik Proxy Leveraging cAdvisor Metrics
2024-05-02Observability Exposed: Exploring Risks in Cloud-Native Metrics
2024-04-22You Can't See Me: Achieving Stealthy Persistence in Azure Machine Learning
2023-08-30Uncovering Silent Threats in Azure Machine Learning Service - Part 2
2023-08-17Uncovering Silent Threats in Azure Machine Learning Service - Part 1
2023-05-23Info Stealer Abusing Codespaces Puts Discord Users at Risk
2023-05-19Rust-Based Info Stealers Abuse GitHub Codespaces
2023-01-16Abusing a GitHub Codespaces Feature For Malware Delivery
2022-10-26Threat Actors Target AWS EC2 Workloads to Steal Credentials
2022-09-12Security Breaks: TeamTNT’s DockerHub Credentials Leak
2022-09-08How Malicious Actors Abuse Native Linux Tools in Attacks
2022-04-08CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability
2022-02-11Detecting PwnKit (CVE-2021-4034) Using Trend Micro Vision One and Cloud One
2022-01-27How to detect Apache Log4j vulnerabilities
2021-12-21How to detect Apache HTTP Server Exploitation
2021-12-03Vulnerabilities Exploited for Monero Mining Malware Delivered via GitHub, Netlify
2021-12-01Analyzing How TeamTNT Used Compromised Docker Hub Accounts
2021-11-09Compromised Docker Hub Accounts Abused for Cryptomining Linked to TeamTNT
2021-08-12Detecting PrintNightmare Exploitation Attempts using Cloud One and Vision One
2021-07-22Safeguarding against cryptomining attacks
2021-04-21Could the Microsoft Exchange breach be stopped?
Talks
ZDI Disclosures

Vulnerabilities identified and reported to vendors in the latest version of their affected product(s).

AdvisorySeverityVulnerability
ZDI-25-10577.8(0Day) Microsoft Visual Studio VsDevCmd Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-25-8588.8Axis Communications Autodesk Plugin AzureBlobRestAPI axiscontentfiles Remote Code Execution Vulnerability
ZDI-25-8444.7Microsoft Windows Subsystem for Linux WslCoreVm::Initialize Incorrect Privilege Management Information Disclosure Vulnerability
ZDI-25-4223.7Microsoft Azure Machine Learning Environments Denial-of-Service Vulnerability
ZDI-25-4215.3Microsoft Azure App Services Information Disclosure Vulnerability
ZDI-25-3597.8Microsoft Visual Studio initializeCommand Insufficient UI Warning Remote Code Execution Vulnerability
ZDI-25-2069.8Amazon AWS CloudFormation Templates Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-25-2059.8Amazon AWS CloudFormation Templates Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-13298.8Axis Communications Autodesk Plugin AxisAddin axisapphelpfiles Remote Code Execution Vulnerability
ZDI-24-13288.8Axis Communications Autodesk Plugin AzureBlobRestAPI axiscontentfiles Remote Code Execution Vulnerability
ZDI-24-11817.6Axis Communications Autodesk Plugin Exposure of Sensitive Information Authentication Bypass Vulnerability
ZDI-24-11779.8Amazon AWS CloudFormation Templates Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-11769.8Amazon AWS aws-glue-with-s2s-vpn Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10979.9(0Day) Microsoft GitHub Dev-Containers Improper Privilege Management Privilege Escalation Vulnerability
ZDI-24-10759.8Microsoft PowerShell Reference for Office Products officedocs-cdn Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10749.8Microsoft PowerShell Gallery psg-prod-centralus Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10739.8Microsoft Azure uAMQP azure-iot-sdks-ci Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10729.8Microsoft CameraTraps cameratracrsppftkje Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10719.8Microsoft Azure GPT ALE palantirdemoacr Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10709.8Microsoft Partner Resources openhacks Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10699.8Microsoft Technical Case Studies athena-dashboard Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10685.3Microsoft Azure ML.NET Samples mlnetfilestorage Uncontrolled Search Path Element Vulnerability
ZDI-24-10679.4Microsoft Azure CollectSFData docs-analytics-eus Uncontrolled Search Path Element Impersonation Vulnerability
ZDI-24-10669.8Microsoft Azure DataStoriesSamples machinelearningdatasets Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10659.8Microsoft Azure Availability Monitor for Kafka esnewdeveastdockerregistry Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10649.8Microsoft AirSim airsimci Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10639.8Microsoft Reactor Workshops reactorworkshops Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10629.8Microsoft Fluid Framework prague Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10619.8Microsoft What The Hack docsmsftpdfs Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10609.8Microsoft Azure Aztack aztack1528763526 Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10599.8Microsoft Azure Linux Automation konkaciwestus1 Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-10589.8Microsoft Azure NodeJS LogPoint logpointsassets Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-23-15888.8Microsoft Azure US Accelarators Synapse SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
ZDI-23-152810.0Microsoft PC Manager SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
ZDI-23-152710.0Microsoft PC Manager SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
ZDI-23-10564.4(0Day) Microsoft Azure Machine Learning Compute Instance certificate Exposure of Resource to Wrong Sphere Information Disclosure Vulnerability
ZDI-23-10449.9(0Day) Microsoft GitHub Dev-Containers Improper Privilege Management Privilege Escalation Vulnerability
ZDI-24-9988.2KernelCI SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
ZDI-24-9937.5Microsoft Azure myapiendpoint.developer.azure-api Improper Access Control Information Disclosure Vulnerability
ZDI-24-9929.8Microsoft Azure VSTS CLI vstscli Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9919.8Microsoft Azure Arc Jumpstart Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9899.8Microsoft Azure Container Network Management sbidprod Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9889.8Microsoft Azure MQTT azure-iot-sdks-ci Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9879.8Microsoft Object Detection Solution Accelerator csaddevamlacr Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9869.8Microsoft Azure IoT Edge Dev Tool iotedgetoolscontainerregistry Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9859.8Microsoft Azure Service Fabric servicefabricsdkstorage Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9839.8Microsoft Azure Go Labs microsoftgoproxy Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9825.3Microsoft Azure SQL Workshop azuremlsampleexperiments Uncontrolled Search Path Element Vulnerability
ZDI-24-9819.8Microsoft Azure Machine Learning Notebooks azuremlpackages Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-9809.8Microsoft Azure Machine Learning Forecasting Toolkit azuremlftkrelease Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-58110.0Microsoft Azure SQL Managed Instance Documentation SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
ZDI-24-5809.8Microsoft Artifact Registry Container Images Empty Password Authentication Bypass Vulnerability
ZDI-24-4009.8Microsoft uAMQP for Python azure-iot-sdks-ci Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-3969.8Microsoft Azure ODSP nikisos Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-24-3695.3Google cAdvisor REST API Improper Access Control Information Disclosure Vulnerability
ZDI-24-2089.8Microsoft Azure MCR VSTS CLI vstscli Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-23-8805.5Microsoft Azure Machine Learning Service DSIMountAgent Missing Authentication Information Disclosure Vulnerability
ZDI-23-3806.5Microsoft Azure Machine Learning Service DSIMountAgent Missing Authentication Information Disclosure Vulnerability
ZDI-23-1616.5Microsoft Azure Machine Learning Service Cleartext Storage of Credentials Information Disclosure Vulnerability
ZDI-23-0976.8Microsoft Azure Machine Learning Service JWT Cleartext Storage of Credentials Information Disclosure Vulnerability
ZDI-23-0966.5Microsoft Azure Machine Learning Service Cleartext Storage of Credentials Information Disclosure Vulnerability
ZDI-23-0956.5Microsoft Azure Machine Learning Service Cleartext Storage of Credentials Information Disclosure Vulnerability
Misc