Skip to main content
← CVE Tracker

Vendor

AWS

31 articles

Advertisement

Cloud Security Index 2026: Multi-Cloud Risk Analysis
INFO
Cloud Security

Cloud Security Index 2026: Multi-Cloud Risk Analysis

Intruder analyzed cloud misconfigurations across AWS, Azure, and GCP, revealing distinct risk profiles and universal IAM challenges.

Runtime Rebel Intel
2 min read · Sep 7, 2026
CVE-2026-63077: JetBrains Cadence Breach Exposes Credentials
CRITICAL
Data Breach

CVE-2026-63077: JetBrains Cadence Breach Exposes Credentials

JetBrains Cadence suffered a data breach via unpatched TeamCity (CVE-2026-63077), exposing AWS credentials, source code, and user data. Immediate action required.

Runtime Rebel Intel
4 min read · Sep 5, 2026
HIGH
Cloud Security

Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts

Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.

Runtime Rebel Intel
3 min read · Aug 21, 2026
HIGH
Data Breach

Beacon CRM Data Breach Exposes Over 1,000 Charity Databases

Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.

Runtime Rebel Intel
4 min read · Aug 16, 2026
HIGH
Threat Intel

North Korea Attribution, Data Breaches Impact OnTrac & UK Education

AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.

Runtime Rebel Intel
4 min read · Jul 31, 2026
AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide
HIGH
Cloud Security

AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide

Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.

Runtime Rebel Intel
4 min read · Jul 21, 2026
HIGH
Threat Intel

CISA GitHub Leak: Lessons from AWS Govcloud Credential Exposure

Analysis of CISA's recent GitHub leak, detailing the exposure of AWS Govcloud keys and internal credentials, and providing critical lessons for cloud security.

Runtime Rebel Intel
4 min read · Jul 13, 2026
HIGH
Cloud Security

Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories

AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.

Runtime Rebel Intel
4 min read · Jun 26, 2026
Kali365 Phishing-as-a-Service Expands to Target AWS and Okta
HIGH
Threat Intel

Kali365 Phishing-as-a-Service Expands to Target AWS and Okta

The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.

Runtime Rebel Intel
4 min read · Jun 3, 2026
HIGH
Cloud Security

CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository

A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Data Breach

CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo

Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.

Runtime Rebel Intel
4 min read · May 22, 2026
Securing Identity Attack Paths: Protecting Cached AWS Credentials
MEDIUM
Identity & Access

Securing Identity Attack Paths: Protecting Cached AWS Credentials

Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.

Runtime Rebel Intel
3 min read · May 21, 2026
HIGH
Cloud Security

CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure

A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development.

Runtime Rebel Intel
5 min read · May 19, 2026
HIGH
Data Breach

Braintrust AWS Breach: Immediate AI Provider API Key Rotation Required

Braintrust prompts users to rotate API keys after unauthorized AWS account access compromised AI provider secrets. Learn about the impact and mitigation.

Runtime Rebel Intel
3 min read · May 8, 2026
HIGH
Malware

PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments

PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.

Runtime Rebel Intel
4 min read · May 8, 2026
MEDIUM
Threat Intel

Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure

Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.

Runtime Rebel Intel
4 min read · May 4, 2026
INFO
Threat Intel

US DoD Partners with 7 Tech Giants for Classified AI Integration

The US Department of Defense secures deals with AWS, Google, and OpenAI to integrate AI into classified environments, focusing on operational decision-making.

Runtime Rebel Intel
4 min read · May 3, 2026
UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse
HIGH
Cloud Security

UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse

Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom 'Snow' malware and AWS S3 cloud abuse in multi-pronged attacks.

Runtime Rebel Intel
5 min read · Apr 27, 2026
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
HIGH
Threat Intel

APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting

China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.

Runtime Rebel Intel
4 min read · Apr 13, 2026
Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
HIGH
Vulnerabilities

Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems

Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.

Runtime Rebel Intel
4 min read · Apr 8, 2026
HIGH
Supply Chain

European Commission AWS Breach: Trivy Supply Chain Attack Analysis

The European Commission confirms a 300GB data breach in its AWS environment linked to a Trivy supply chain attack. Learn about the impact and mitigations.

Runtime Rebel Intel
4 min read · Apr 4, 2026
CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets
HIGH
Threat Intel

CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets

Attackers are exploiting the CVE-2025-55182 React2Shell vulnerability in Next.js to harvest AWS secrets, SSH keys, and database credentials from 766 hosts.

Runtime Rebel Intel
3 min read · Apr 3, 2026
HIGH
Cloud Security

EC Investigates Breach After IntelBroker Claims AWS Account Hack

The European Commission is investigating a security breach of its AWS infrastructure after threat actor IntelBroker claimed to have stolen user database records.

Runtime Rebel Intel
4 min read · Mar 27, 2026
AWS Bedrock AI Agent Security: Analysis of Eight Attack Vectors
HIGH
Cloud Security

AWS Bedrock AI Agent Security: Analysis of Eight Attack Vectors

Research identifies eight critical attack vectors in AWS Bedrock, focusing on risks to integrated enterprise data and automated Lambda function execution.

Runtime Rebel Intel
4 min read · Mar 23, 2026