North Korea Attribution, Data Breaches Impact OnTrac & UK Education
AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.
AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide
Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.
CISA GitHub Leak: Lessons from AWS Govcloud Credential Exposure
Analysis of CISA's recent GitHub leak, detailing the exposure of AWS Govcloud keys and internal credentials, and providing critical lessons for cloud security.
Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories
AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.
Kali365 Phishing-as-a-Service Expands to Target AWS and Okta
The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.
CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository
A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.
CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo
Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.
Securing Identity Attack Paths: Protecting Cached AWS Credentials
Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.
CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure
A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development.
Braintrust AWS Breach: Immediate AI Provider API Key Rotation Required
Braintrust prompts users to rotate API keys after unauthorized AWS account access compromised AI provider secrets. Learn about the impact and mitigation.
PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments
PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.
Amazon SES Phishing Abuse: Evading Security Filters via AWS Infrastructure
Threat actors are increasingly exploiting Amazon Simple Email Service (SES) to bypass email security filters by leveraging high-reputation AWS domains.
US DoD Partners with 7 Tech Giants for Classified AI Integration
The US Department of Defense secures deals with AWS, Google, and OpenAI to integrate AI into classified environments, focusing on operational decision-making.
UNC6692 Leverages Teams, AWS S3 for Malware & Cloud Abuse
Newly discovered threat actor UNC6692 combines social engineering via Microsoft Teams with custom 'Snow' malware and AWS S3 cloud abuse in multi-pronged attacks.
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.
Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.
European Commission AWS Breach: Trivy Supply Chain Attack Analysis
The European Commission confirms a 300GB data breach in its AWS environment linked to a Trivy supply chain attack. Learn about the impact and mitigations.
CVE-2025-55182: Next.js React2Shell Exploited to Steal Cloud Secrets
Attackers are exploiting the CVE-2025-55182 React2Shell vulnerability in Next.js to harvest AWS secrets, SSH keys, and database credentials from 766 hosts.
EC Investigates Breach After IntelBroker Claims AWS Account Hack
The European Commission is investigating a security breach of its AWS infrastructure after threat actor IntelBroker claimed to have stolen user database records.
AWS Bedrock AI Agent Security: Analysis of Eight Attack Vectors
Research identifies eight critical attack vectors in AWS Bedrock, focusing on risks to integrated enterprise data and automated Lambda function execution.
Native Launches Multicloud Security Control Plane for Policy Enforcement
Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.
Tech Giants Pledge $12.5M to Bolster Open Source Software Security
Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.
Chrome Zero-Days and Router Botnets: Weekly Threat Intel Recap
Analysis of the latest Chrome zero-day vulnerabilities, router botnet infrastructure risks, and AWS cloud security breaches from March 2026.
UNC6426 Exploits nx npm Supply-Chain Attack for AWS Admin Access
UNC6426 leveraged stolen GitHub tokens from the nx npm compromise to achieve full AWS administrative control and data exfiltration within 72 hours.