All CosmicBytez Labs articles tagged #AWS, across news, security advisories, how-to guides, and projects.
hulumi/policies before 1.3.2 let attackers suppress guardrail violations using compliant evidence from an unrelated resource in the same stack.
hulumi/policies before 1.3.2 missed set-qualified IAM operators, letting wildcard GitHub Actions OIDC conditions slip past guardrails.
hulumi before 1.3.2 let attackers create persistent higher-privilege af-e2e-* roles in the sandbox account via a flawed IAM boundary.
Truffle Security found 64,000 unique live AWS keys in public sources — 526 are root keys, 88% still authenticate, median age 5 years.
Over 9,300 AWS access keys exposed publicly between 2022 and 2026 remain valid and active, giving attackers full control over corporate cloud accounts.
CareCloud confirmed 3.75 million patients had medical records, SSNs, and financial data stolen in a March 2026 AWS intrusion — fifth-largest health breach of 2026.
CareCloud's cloud EHR platform suffered a 6-day AWS breach in March 2026, exposing health and personal data of 3.75 million patients.
Critical unauthenticated SSRF in MLflow's webhook system lets attackers redirect requests to steal AWS credentials. Upgrade to 3.15.0.
Over 1,000 UK charities affected after Beacon CRM suffered a data breach traced to an exposed AWS access key in public JS files.
An improper link resolution vulnerability in AWS Research and Engineering Studio (RES) allows authenticated users to replace their SSH key with a symlink, causing the cluster-manager process (running as root) to return the contents of any root-readable file on the host — including other users' private keys and application secrets.
A critical vulnerability in @fastify/aws-lambda 6.4.0 allows attackers to spoof AWS API Gateway authorizer claims by sending crafted HTTP headers, bypassing authorization logic in Fastify applications deployed on AWS Lambda.
This week's security roundup covers a parcel delivery company breach at OnTrac, Adobe's latest security patches, AWS attribution of recent cloud attacks to North Korean threat actors, an OpenAI open source security tool release, and Mythos crypto research targeting DeFi protocols.
Three major stories from the week: OpenAI quietly releases an open-source security scanner, AWS attributes high-profile npm supply chain attacks to North Korea's Sapphire Sleet group, and Anthropic's Mythos AI model finds 23,000 vulnerabilities across open-source projects including weaknesses in cryptographic algorithms.
CISA has published a postmortem on a data leak in which a contractor exposed dozens of internal credentials — including AWS GovCloud keys — in a public...
A single threat actor leveraged AI workflows, chained cloud misconfigurations, and stolen credentials to breach a large Amazon Web Services customer...
The UK government's voluntary Cyber Resilience Pledge attracted fewer than 15 of Britain's 350 largest listed companies despite eight months of direct...
Gitea versions through 1.26.2 use an incomplete IP filter that allows authenticated users to reach AWS Instance Metadata, Azure WireServer, and...
This week's security roundup covers Apple's patch for a Beats headphones eavesdropping vulnerability, the DOT closing its investigation into Delta's...
Security researchers have disclosed three now-patched vulnerabilities in LangGraph — including a critical chain that enables remote code execution on...
This week's security roundup covers Linux privilege escalation zero-days, actively exploited Windows Defender vulnerabilities, router botnets hijacking DNS.
Members of Congress are demanding answers from CISA after a contractor intentionally published AWS GovCloud access keys and a trove of agency secrets on a...
The Amazon Redshift Python driver before version 2.1.14 contains a critical vulnerability where the vector_in() function executes arbitrary code received...
Other noteworthy stories this week: Big Tech firms push back against Canada's encryption legislation, Cisco releases a free AI security specification, and...
A critical unauthenticated vulnerability in Plunk, the open-source AWS SES email platform, allows attackers to forge Amazon SNS webhook payloads without...
Anthropic's new Project Glasswing initiative uses a preview of its frontier model Claude Mythos to autonomously discover thousands of previously unknown...
The European Commission has confirmed a major data breach of its AWS environment, with over 300GB of data stolen — including personal information of EU...
Improper certificate validation in Amazon Athena ODBC driver versions prior to 2.1.0.0 allows man-in-the-middle attackers to intercept authentication...
A large-scale credential harvesting campaign has been observed exploiting the React2Shell vulnerability (CVE-2025-55182) as an initial infection vector,...
The European Commission is investigating a security breach after a threat actor gained unauthorized access to its Amazon Web Services cloud environment...
The European Commission confirms a 350 GB AWS breach; the DarkSword iOS exploit chain goes public on GitHub threatening hundreds of millions of iPhones;...
Native, founded by ex-AWS security leaders, has emerged from stealth with $42 million in backing from Ballistic Ventures and General Catalyst to build the...
Security researchers disclosed critical flaws across three major AI platforms: Amazon Bedrock AgentCore's sandbox can be bypassed via DNS to exfiltrate...
Threat actor UNC6426 leveraged stolen credentials from last year's nx npm supply chain attack to achieve full AWS administrator access at a victim...
Harden your CI/CD pipeline by replacing long-lived secrets with OIDC short-lived tokens, pinning third-party actions to commit SHAs, enforcing...
LexisNexis Legal & Professional confirms a data breach after threat actor FulcrumSec exploited an unpatched React2Shell vulnerability to exfiltrate 2.04...
A routine configuration update at Cloudflare's Ashburn data center introduced a BGP routing error on February 16 that cascaded across the internet,...
Researchers uncover VoidLink, an 88,000-line Zig-based malware framework built with AI assistance that targets AWS, Azure, GCP, and Kubernetes environments.
Pre-migration checklist for moving workloads to Azure, AWS, or GCP. Covers assessment, planning, security, networking, cost management, and go-live validation.
Implement AWS Security Hub for centralized security findings across accounts. Covers security standards, GuardDuty/Inspector integration, custom insights,...