<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #AWS</title><description>Cybersecurity articles tagged #AWS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cloud Security Index 2026: Multi-Cloud Risk Analysis</title><link>https://runtimerebel.com/blog/cloud-security-index-2026-multi-cloud-risk-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloud-security-index-2026-multi-cloud-risk-analysis</guid><description>Intruder analyzed cloud misconfigurations across AWS, Azure, and GCP, revealing distinct risk profiles and universal IAM challenges.</description><pubDate>Mon, 07 Sep 2026 13:49:04 GMT</pubDate><category>Cloud Security</category><category>Google Cloud</category><category>IAM</category><category>Misconfiguration</category><category>AWS</category></item><item><title>Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts</title><link>https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</guid><description>Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.</description><pubDate>Fri, 21 Aug 2026 16:21:53 GMT</pubDate><category>AWS</category><category>Credential Theft</category><category>Cloud Security</category><category>IAM</category><category>Data Breach</category></item><item><title>North Korea Attribution, Data Breaches Impact OnTrac &amp; UK Education</title><link>https://runtimerebel.com/blog/north-korea-attribution-data-breaches-impact-ontrac-uk-education</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-attribution-data-breaches-impact-ontrac-uk-education</guid><description>AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.</description><pubDate>Fri, 31 Jul 2026 17:43:11 GMT</pubDate><category>North Korea</category><category>APT</category><category>Data Breach</category><category>Ontrac</category><category>UK Department for Education</category><category>AWS</category></item><item><title>AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide</title><link>https://runtimerebel.com/blog/aws-kiro-rce-via-indirect-prompt-injection-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/aws-kiro-rce-via-indirect-prompt-injection-mitigation-guide</guid><description>Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.</description><pubDate>Tue, 21 Jul 2026 17:22:23 GMT</pubDate><category>AWS</category><category>Kiro</category><category>RCE</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories</title><link>https://runtimerebel.com/blog/amazon-q-flaw-cloud-credential-theft-via-malicious-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/amazon-q-flaw-cloud-credential-theft-via-malicious-repositories</guid><description>AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.</description><pubDate>Fri, 26 Jun 2026 16:48:25 GMT</pubDate><category>Amazon Q</category><category>AWS</category><category>Cloud Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>Vulnerability</category><category>Patching</category></item><item><title>Amazon Q Developer RCE via CVE-2026-12957 - Cloud Credential Theft</title><link>https://runtimerebel.com/blog/amazon-q-developer-rce-via-cve-2026-12957-cloud-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/amazon-q-developer-rce-via-cve-2026-12957-cloud-credential-theft</guid><description>High-severity CVE-2026-12957 in Amazon Q Developer allowed malicious repositories to execute arbitrary code and steal cloud credentials upon workspace trust. Patch now.</description><pubDate>Fri, 26 Jun 2026 16:47:43 GMT</pubDate><category>CVE-2026-12957</category><category>Amazon Q Developer</category><category>RCE</category><category>Cloud Security</category><category>AWS</category><category>Wiz</category></item><item><title>Kali365 Phishing-as-a-Service Expands to Target AWS and Okta</title><link>https://runtimerebel.com/blog/kali365-phishing-as-a-service-expands-to-target-aws-and-okta</link><guid isPermaLink="true">https://runtimerebel.com/blog/kali365-phishing-as-a-service-expands-to-target-aws-and-okta</guid><description>The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.</description><pubDate>Wed, 03 Jun 2026 05:44:29 GMT</pubDate><category>Kali365</category><category>Phishing as a Service</category><category>MFA Bypass</category><category>Cloud Security</category><category>AWS</category><category>Okta</category></item><item><title>Securing Identity Attack Paths: Protecting Cached AWS Credentials</title><link>https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</guid><description>Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.</description><pubDate>Thu, 21 May 2026 13:17:05 GMT</pubDate><category>AWS</category><category>Identity Security</category><category>Cloud Security</category><category>Lateral Movement</category><category>IAM</category></item><item><title>APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting</title><link>https://runtimerebel.com/blog/apt41-deploys-stealth-backdoor-for-cloud-credential-harvesting</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt41-deploys-stealth-backdoor-for-cloud-credential-harvesting</guid><description>China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.</description><pubDate>Mon, 13 Apr 2026 16:35:11 GMT</pubDate><category>APT41</category><category>Cloud Security</category><category>Credential Harvesting</category><category>AWS</category><category>Azure</category><category>Backdoor</category></item><item><title>EC Investigates Breach After IntelBroker Claims AWS Account Hack</title><link>https://runtimerebel.com/blog/ec-investigates-breach-after-intelbroker-claims-aws-account-hack</link><guid isPermaLink="true">https://runtimerebel.com/blog/ec-investigates-breach-after-intelbroker-claims-aws-account-hack</guid><description>The European Commission is investigating a security breach of its AWS infrastructure after threat actor IntelBroker claimed to have stolen user database records.</description><pubDate>Fri, 27 Mar 2026 16:24:50 GMT</pubDate><category>European Commission</category><category>IntelBroker</category><category>AWS</category><category>Identity Access Management</category><category>Data Breach</category></item><item><title>Chrome Zero-Days and Router Botnets: Weekly Threat Intel Recap</title><link>https://runtimerebel.com/blog/chrome-zero-days-and-router-botnets-weekly-threat-intel-recap</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-zero-days-and-router-botnets-weekly-threat-intel-recap</guid><description>Analysis of the latest Chrome zero-day vulnerabilities, router botnet infrastructure risks, and AWS cloud security breaches from March 2026.</description><pubDate>Mon, 16 Mar 2026 16:28:15 GMT</pubDate><category>Chrome</category><category>Botnets</category><category>AWS</category><category>Zero-Day</category><category>AI Security</category></item><item><title>AWS Honeytoken Implementation: Proactive Detection of IAM Credential Theft</title><link>https://runtimerebel.com/blog/aws-honeytoken-implementation-proactive-detection-of-iam-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/aws-honeytoken-implementation-proactive-detection-of-iam-credential-theft</guid><description>Learn how to implement AWS honeytokens using IAM and CloudTrail to detect unauthorized credential usage and mitigate lateral movement in cloud environments.</description><pubDate>Mon, 09 Mar 2026 04:41:00 GMT</pubDate><category>AWS</category><category>Honeytokens</category><category>IAM</category><category>CloudTrail</category><category>Detection Engineering</category></item><item><title>Geopolitical Strikes on AWS Data Centers: Mitigating Physical Disaster Risk</title><link>https://runtimerebel.com/blog/geopolitical-strikes-on-aws-data-centers-mitigating-physical-disaster-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-strikes-on-aws-data-centers-mitigating-physical-disaster-risk</guid><description>Iranian drone strikes damaged AWS data centers in UAE and Bahrain, highlighting critical vulnerabilities to physical disasters and the urgent need for geo-redundancy.</description><pubDate>Tue, 03 Mar 2026 20:12:52 GMT</pubDate><category>AWS</category><category>Data Center</category><category>Physical Attack</category><category>Iran</category><category>Cloud Security</category><category>Disaster Recovery</category><category>Geopolitical Threat</category></item><item><title>Automated AI-Driven Exploitation of FortiGate Management Interfaces in AWS Environments</title><link>https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</guid><description>Threat actors are utilizing artificial intelligence to automate credential stuffing and exploit exposed administrative ports on Fortinet devices within AWS…</description><pubDate>Mon, 23 Feb 2026 12:21:29 GMT</pubDate><category>FortiGate</category><category>AWS</category><category>Credential Stuffing</category><category>AI</category><category>Network Security</category></item></channel></rss>