Problem Statement
Which misconfiguration led to the 2019 Capital One data breach?
Explanation
A misconfigured Web Application Firewall allowed an attacker to exploit a server-side request forgery vulnerability and access AWS instance metadata. This exposed customer data stored in S3 buckets. The incident showed how misconfiguration in cloud security tools can cause large-scale data exposure.
