Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
39 articles

#AWS

All CosmicBytez Labs articles tagged #AWS, across news, security advisories, how-to guides, and projects.

  • SecuritySep 1, 2026

    CVE-2026-82855: @hulumi/policies Cross-Resource Evidence Validation Bypass

    hulumi/policies before 1.3.2 let attackers suppress guardrail violations using compliant evidence from an unrelated resource in the same stack.

  • SecuritySep 1, 2026

    CVE-2026-82856: @hulumi/policies GitHub OIDC Trust Policy Bypass

    hulumi/policies before 1.3.2 missed set-qualified IAM operators, letting wildcard GitHub Actions OIDC conditions slip past guardrails.

  • SecuritySep 1, 2026

    CVE-2026-82857: hulumi Privilege Escalation via Weekly Integration IAM Policy

    hulumi before 1.3.2 let attackers create persistent higher-privilege af-e2e-* roles in the sandbox account via a flawed IAM boundary.

  • NewsAug 23, 2026

    768 Live AWS Keys with Full Admin Access Found Across Public Repos, AI Training Data, and Docker Images

    Truffle Security found 64,000 unique live AWS keys in public sources — 526 are root keys, 88% still authenticate, median age 5 years.

  • NewsAug 22, 2026

    9,300+ Leaked AWS Keys Still Active, Granting Full Corporate Account Control

    Over 9,300 AWS access keys exposed publicly between 2022 and 2026 remain valid and active, giving attackers full control over corporate cloud accounts.

  • NewsAug 20, 2026

    Healthtech Firm CareCloud Data Breach Impacts 3.7 Million Patients

    CareCloud confirmed 3.75 million patients had medical records, SSNs, and financial data stolen in a March 2026 AWS intrusion — fifth-largest health breach of 2026.

  • NewsAug 19, 2026

    CareCloud Data Breach Exposes 3.75 Million Patient Records

    CareCloud's cloud EHR platform suffered a 6-day AWS breach in March 2026, exposing health and personal data of 3.75 million patients.

  • SecurityAug 19, 2026

    CVE-2026-64849: MLflow SSRF Webhook Bypass Actively Exploited

    Critical unauthenticated SSRF in MLflow's webhook system lets attackers redirect requests to steal AWS credentials. Upgrade to 3.15.0.

  • NewsAug 14, 2026

    Over 1,000 Charities Hit by Beacon CRM Data Breach

    Over 1,000 UK charities affected after Beacon CRM suffered a data breach traced to an exposed AWS access key in public JS files.

  • SecurityAug 7, 2026

    AWS Research and Engineering Studio Symlink File Read Exposes Root-Accessible Secrets

    An improper link resolution vulnerability in AWS Research and Engineering Studio (RES) allows authenticated users to replace their SSH key with a symlink, causing the cluster-manager process (running as root) to return the contents of any root-readable file on the host — including other users' private keys and application secrets.

  • SecurityAug 4, 2026

    CVE-2026-18248: Fastify AWS Lambda Auth Bypass Allows Privilege Escalation

    A critical vulnerability in @fastify/aws-lambda 6.4.0 allows attackers to spoof AWS API Gateway authorizer claims by sending crafted HTTP headers, bypassing authorization logic in Fastify applications deployed on AWS Lambda.

  • NewsAug 2, 2026

    In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research

    This week's security roundup covers a parcel delivery company breach at OnTrac, Adobe's latest security patches, AWS attribution of recent cloud attacks to North Korean threat actors, an OpenAI open source security tool release, and Mythos crypto research targeting DeFi protocols.

  • NewsAug 1, 2026

    Security Roundup: OpenAI Open Sources Codex Security CLI, AWS Pins NPM Attacks on North Korea, Anthropic Mythos Cracks Crypto

    Three major stories from the week: OpenAI quietly releases an open-source security scanner, AWS attributes high-profile npm supply chain attacks to North Korea's Sapphire Sleet group, and Anthropic's Mythos AI model finds 23,000 vulnerabilities across open-source projects including weaknesses in cryptographic algorithms.

  • NewsJul 13, 2026

    Lessons Learned from CISA's Recent GitHub Leak

    CISA has published a postmortem on a data leak in which a contractor exposed dozens of internal credentials — including AWS GovCloud keys — in a public...

  • NewsJul 9, 2026

    Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

    A single threat actor leveraged AI workflows, chained cloud misconfigurations, and stolen credentials to breach a large Amazon Web Services customer...

  • NewsJul 7, 2026

    UK Cyber Pledge Draws Only a Handful of Top Firms Despite Ministerial Appeal

    The UK government's voluntary Cyber Resilience Pledge attracted fewer than 15 of Britain's 350 largest listed companies despite eight months of direct...

  • SecurityJul 4, 2026

    CVE-2026-22874: Gitea SSRF Filter Bypass Exposes Cloud Credentials

    Gitea versions through 1.26.2 use an incomplete IP filter that allows authenticated users to reach AWS Instance Metadata, Azure WireServer, and...

  • NewsJun 21, 2026

    In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum

    This week's security roundup covers Apple's patch for a Beats headphones eavesdropping vulnerability, the DOT closing its investigation into Delta's...

  • NewsJun 12, 2026

    LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

    Security researchers have disclosed three now-patched vulnerabilities in LangGraph — including a critical chain that enables remote code execution on...

  • NewsMay 25, 2026

    Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets

    This week's security roundup covers Linux privilege escalation zero-days, actively exploited Windows Defender vulnerabilities, router botnets hijacking DNS.

  • NewsMay 22, 2026

    Lawmakers Demand Answers as CISA Tries to Contain Data Leak

    Members of Congress are demanding answers from CISA after a contractor intentionally published AWS GovCloud access keys and a trove of agency secrets on a...

  • SecurityMay 19, 2026

    CVE-2026-8838 — Amazon Redshift Python Driver RCE via Unsafe Code Execution

    The Amazon Redshift Python driver before version 2.1.14 contains a critical vulnerability where the vector_in() function executes arbitrary code received...

  • NewsMay 16, 2026

    In Other News: Big Tech vs Canada Encryption Bill, Cisco's

    Other noteworthy stories this week: Big Tech firms push back against Canada's encryption legislation, Cisco releases a free AI security specification, and...

  • SecurityMay 9, 2026

    CVE-2026-42193: Plunk Email Platform SNS Webhook Forgery

    A critical unauthenticated vulnerability in Plunk, the open-source AWS SES email platform, allows attackers to forge Amazon SNS webhook payloads without...

  • NewsApr 8, 2026

    Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws

    Anthropic's new Project Glasswing initiative uses a preview of its frontier model Claude Mythos to autonomously discover thousands of previously unknown...

  • NewsApr 4, 2026

    European Commission Confirms Data Breach Linked to Trivy

    The European Commission has confirmed a major data breach of its AWS environment, with over 300GB of data stolen — including personal information of EU...

  • SecurityApr 4, 2026

    CVE-2026-35560: Amazon Athena ODBC Driver Fails Certificate

    Improper certificate validation in Amazon Athena ODBC driver versions prior to 2.1.0.0 allows man-in-the-middle attackers to intercept authentication...

  • NewsApr 2, 2026

    Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts

    A large-scale credential harvesting campaign has been observed exploiting the React2Shell vulnerability (CVE-2025-55182) as an initial infection vector,...

  • NewsMar 27, 2026

    European Commission Investigating Breach After Amazon Cloud

    The European Commission is investigating a security breach after a threat actor gained unauthorized access to its Amazon Web Services cloud environment...

  • NewsletterMar 27, 2026

    Mar 27 Digest: EU Commission AWS Breach, DarkSword iOS

    The European Commission confirms a 350 GB AWS breach; the DarkSword iOS exploit chain goes public on GitHub threatening hundreds of millions of iPhones;...

  • NewsMar 18, 2026

    Cloud Security Startup Native Exits Stealth With $42

    Native, founded by ex-AWS security leaders, has emerged from stealth with $42 million in backing from Ballistic Ventures and General Catalyst to build the...

  • NewsMar 17, 2026

    AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

    Security researchers disclosed critical flaws across three major AI platforms: Amazon Bedrock AgentCore's sandbox can be bypassed via DNS to exfiltrate...

  • NewsMar 11, 2026

    UNC6426 Weaponizes Old nx npm Compromise to Seize AWS Admin Access

    Threat actor UNC6426 leveraged stolen credentials from last year's nx npm supply chain attack to achieve full AWS administrator access at a victim...

  • HOWTOMar 9, 2026

    How to Secure GitHub Actions Workflows with OIDC, SHA

    Harden your CI/CD pipeline by replacing long-lived secrets with OIDC short-lived tokens, pinning third-party actions to commit SHAs, enforcing...

  • NewsMar 4, 2026

    LexisNexis Confirms Cloud Breach Exposing 400K User

    LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...

  • NewsFeb 16, 2026

    Cloudflare BGP Routing Error Cascades Across AWS, X, and More

    A routine configuration update at Cloudflare's Ashburn data center introduced a BGP routing error on February 16 that cascaded across the internet,...

  • NewsFeb 9, 2026

    VoidLink: AI-Generated Cloud-Native Malware Framework

    Researchers uncover VoidLink, an 88,000-line Zig-based malware framework built with AI assistance that targets AWS, Azure, GCP, and Kubernetes environments.

  • ChecklistFeb 8, 2026

    Cloud Migration Readiness Checklist

    Pre-migration checklist for moving workloads to Azure, AWS, or GCP. Covers assessment, planning, security, networking, cost management, and go-live validation.

  • HOWTOFeb 3, 2026

    AWS Security Hub: Centralized Security Findings

    Implement AWS Security Hub for centralized security findings across accounts. Covers security standards, GuardDuty/Inspector integration, custom insights,...