Capital One (2019): An SSRF Misconfiguration Breach in the Cloud
A factual retrospective on the 2019 Capital One breach, in which a server-side request forgery flaw against a misconfigured WAF allowed access to AWS metadata credentials and over 100 million customer records.