home.social

#awssecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #awssecurity, aggregated by home.social.

fetched live
  1. AgentCore Harness Exposes Credential Risks

    A default-enabled shell in AgentCore Harness can be exploited through prompt injection, allowing attackers to execute commands and extract plaintext credentials from the harness process memory, putting sensitive data at risk. This simple yet consequential chain highlights a critical vulnerability in credential security.

    osintsights.com/agentcore-harn

    #CredentialExfiltration #AgentcoreHarness #AwsSecurity #IdentityTheft #SupplyChainRisks

  2. Aesto Health disclosed a breach of its AWS infrastructure exposing PII and PHI of 9.54 million individuals, disclosed June 2026. The scale and sensitivity of health data significantly increase risk of identity fraud and secondary exploitation. Healthcare cloud environments require continuous hardening and monitoring. #DataBreach #HealthcareSecurity #AwsSecurity

    cyberworldops.eu/en/aesto-heal

  3. Aesto Health disclosed a breach of its AWS infrastructure exposing PII and PHI of 9.54 million individuals, disclosed June 2026. The scale and sensitivity of health data significantly increase risk of identity fraud and secondary exploitation. Healthcare cloud environments require continuous hardening and monitoring. #DataBreach #HealthcareSecurity #AwsSecurity

    cyberworldops.eu/en/aesto-heal

  4. 🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

  5. 🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

  6. 🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

  7. 🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

  8. 🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
    theguptalog.blogspot.com/2026/ #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated

  9. 🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
    theguptalog.blogspot.com/2026/ #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated

  10. 🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
    theguptalog.blogspot.com/2026/ #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated

  11. 🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
    theguptalog.blogspot.com/2026/ #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated

  12. Now on Crucial Exams: AWS Certified Security Specialty (SCS-C03) - 250 practice questions and 220 flashcards to help you pass. Start studying: crucialexams.com/s/hjqNttCN #AWSSecurity

  13. Now on Crucial Exams: AWS Certified Security Specialty (SCS-C03) - 250 practice questions and 220 flashcards to help you pass. Start studying: crucialexams.com/s/hjqNttCN #AWSSecurity

  14. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  15. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  16. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  17. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  18. Could your AWS cloud be secretly exposed? Hackers are exploiting SSRF to snag sensitive metadata, but upgrading to IMDSv2 might just turn the tables. Check out why tightening up this single layer could mean the difference between breach and safety.

    thedefendopsdiaries.com/securi

    #ssrf
    #awssecurity
    #cloudsecurity
    #ec2
    #imdsv2

  19. Could your AWS cloud be secretly exposed? Hackers are exploiting SSRF to snag sensitive metadata, but upgrading to IMDSv2 might just turn the tables. Check out why tightening up this single layer could mean the difference between breach and safety.

    thedefendopsdiaries.com/securi

    #ssrf
    #awssecurity
    #cloudsecurity
    #ec2
    #imdsv2

  20. Quantum computing is shaking up digital security. Legacy encryption could soon be a thing of the past, and AWS is already stepping in with breakthrough ML-KEM tech. Ready to see how we're gearing up for a quantum future?

    thedefendopsdiaries.com/securi

    #quantumcomputing
    #cybersecurity
    #postquantum
    #encryption
    #awssecurity

  21. Imagine classic encryption like RSA being outsmarted by quantum computers. AWS’s new ML-KEM is already paving the way for tomorrow’s cybersecurity—could this be the future-proof solution we need?

    thedefendopsdiaries.com/securi

    #quantumcomputing
    #cybersecurity
    #postquantum
    #encryption
    #awssecurity

  22. Quantum computing is shaking up digital security. Legacy encryption could soon be a thing of the past, and AWS is already stepping in with breakthrough ML-KEM tech. Ready to see how we're gearing up for a quantum future?

    thedefendopsdiaries.com/securi

    #quantumcomputing
    #cybersecurity
    #postquantum
    #encryption
    #awssecurity

  23. Imagine classic encryption like RSA being outsmarted by quantum computers. AWS’s new ML-KEM is already paving the way for tomorrow’s cybersecurity—could this be the future-proof solution we need?

    thedefendopsdiaries.com/securi

    #quantumcomputing
    #cybersecurity
    #postquantum
    #encryption
    #awssecurity

  24. Some early morning coffee and catching up on the latest AWS IAM news and blogs on my Kindle Scribe - love this big screen! Becoming a bit of a habit (a good one too). #aws #awssecurity

  25. Some early morning coffee and catching up on the latest AWS IAM news and blogs on my Kindle Scribe - love this big screen! Becoming a bit of a habit (a good one too). #aws #awssecurity

  26. Some early morning coffee and catching up on the latest AWS IAM news and blogs on my Kindle Scribe - love this big screen! Becoming a bit of a habit (a good one too). #aws #awssecurity

  27. Get the scoop on the latest #AWS shadow resource & S3 Bucket namesquatting attacks in our new 7-minute video! Learn how attackers exploit predictable naming to compromise #cloud infrastructure and how to prevent these attacks. youtu.be/rc4CHfVxezI

    #cloudsecurity #namesquatting #shadowIT #awssecurity

  28. Get the scoop on the latest #AWS shadow resource & S3 Bucket namesquatting attacks in our new 7-minute video! Learn how attackers exploit predictable naming to compromise #cloud infrastructure and how to prevent these attacks. youtu.be/rc4CHfVxezI

    #cloudsecurity #namesquatting #shadowIT #awssecurity

  29. TIL, there's a hard coded client_id in the #AWS #awsconsole for what I suspect is an AWS managed account that handles oauth2.0 for root/some login types.

    The client_id depending on the service that it first redirects looks like this arn:aws:iam:015428540659:user/s3

    Another service that I've noticed is phd-console (Which I think is AWS health dashboard).

    So in this pattern it looks like your secret access key is treated as the client secret in an authorization code flow.

    The code/access token returned by AWS is an opaque encrypted JWT.

    #awssecurity

  30. TIL, there's a hard coded client_id in the #AWS #awsconsole for what I suspect is an AWS managed account that handles oauth2.0 for root/some login types.

    The client_id depending on the service that it first redirects looks like this arn:aws:iam:015428540659:user/s3

    Another service that I've noticed is phd-console (Which I think is AWS health dashboard).

    So in this pattern it looks like your secret access key is treated as the client secret in an authorization code flow.

    The code/access token returned by AWS is an opaque encrypted JWT.

    #awssecurity

  31. 🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.

    youtube.com/watch?v=H7C-qUZm8m

    #AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource

  32. 🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.

    youtube.com/watch?v=H7C-qUZm8m

    #AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource

  33. The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! aws.amazon.com/blogs/security/ #awssecurity #awscloud

  34. The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! aws.amazon.com/blogs/security/ #awssecurity #awscloud

  35. #ChatGPT explaining cross-account Security Group referencing pretty neatly. One of the easiest ways to implement an IP Address-free trust between connected apps in #AWS.

    Also called #microsegmentation.

    FOLLOW US as we explore cloud network security with #AI.

    #awssecurity

  36. We ask #ChatGPT about an oft overlooked policy that you should be putting in place when using #VPC #Endpoints in #AWS. Do NOT inadvertently allow access to other tenants' resources!

    FOLLOW US as we explore cloud network security with #AI.

    #awssecurity

  37. AWS Elastic Container Registry Public (ECR Public) vulnerability:

    =>Hackers can delete, update, and create ECR Public images, layers, and tags in registries and repositories that belong to victims' AWS Accounts

    blog.lightspin.io/aws-ecr-publ

    Credit: @gafnitav @LightspinTech

    #infosec #AwsSecurity #ContainerSecurity #Devops #DevSecops #kubernetes #websecurity