home.social

#awssecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #awssecurity, aggregated by home.social.

fetched live
  1. 🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

  2. 🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! radar.offseq.com/threat/cve-20 #OffSeq #AWSSecurity #Python #CVE2026_12530

  3. 🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
    theguptalog.blogspot.com/2026/ #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated

  4. 🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
    theguptalog.blogspot.com/2026/ #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated

  5. Now on Crucial Exams: AWS Certified Security Specialty (SCS-C03) - 250 practice questions and 220 flashcards to help you pass. Start studying: crucialexams.com/s/hjqNttCN #AWSSecurity

  6. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  7. Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.

    thedefendopsdiaries.com/crimso

    #crimsoncollective
    #awssecurity
    #cloudattacks
    #databreach
    #cyberthreats

  8. Some early morning coffee and catching up on the latest AWS IAM news and blogs on my Kindle Scribe - love this big screen! Becoming a bit of a habit (a good one too). #aws #awssecurity

  9. Get the scoop on the latest #AWS shadow resource & S3 Bucket namesquatting attacks in our new 7-minute video! Learn how attackers exploit predictable naming to compromise #cloud infrastructure and how to prevent these attacks. youtu.be/rc4CHfVxezI

    #cloudsecurity #namesquatting #shadowIT #awssecurity

  10. TIL, there's a hard coded client_id in the #AWS #awsconsole for what I suspect is an AWS managed account that handles oauth2.0 for root/some login types.

    The client_id depending on the service that it first redirects looks like this arn:aws:iam:015428540659:user/s3

    Another service that I've noticed is phd-console (Which I think is AWS health dashboard).

    So in this pattern it looks like your secret access key is treated as the client secret in an authorization code flow.

    The code/access token returned by AWS is an opaque encrypted JWT.

    #awssecurity

  11. 🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.

    youtube.com/watch?v=H7C-qUZm8m

    #AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource

  12. 🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.

    youtube.com/watch?v=H7C-qUZm8m

    #AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource

  13. The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! aws.amazon.com/blogs/security/ #awssecurity #awscloud

  14. The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! aws.amazon.com/blogs/security/ #awssecurity #awscloud

  15. #ChatGPT explaining cross-account Security Group referencing pretty neatly. One of the easiest ways to implement an IP Address-free trust between connected apps in #AWS.

    Also called #microsegmentation.

    FOLLOW US as we explore cloud network security with #AI.

    #awssecurity

  16. We ask #ChatGPT about an oft overlooked policy that you should be putting in place when using #VPC #Endpoints in #AWS. Do NOT inadvertently allow access to other tenants' resources!

    FOLLOW US as we explore cloud network security with #AI.

    #awssecurity

  17. #ChatGPT may have passed law and business exams, but it won't be getting #AWS networking certifications anytime soon.

    9.9.9.9 is not in the 128.0.0.0/1 subnet, and Rules are not evaluated sequentially 🤦

    FOLLOW US as we explore cloud networking security with #AI!

    #awssecurity

  18. AWS Elastic Container Registry Public (ECR Public) vulnerability:

    =>Hackers can delete, update, and create ECR Public images, layers, and tags in registries and repositories that belong to victims' AWS Accounts

    blog.lightspin.io/aws-ecr-publ

    Credit: @gafnitav @LightspinTech

    #infosec #AwsSecurity #ContainerSecurity #Devops #DevSecops #kubernetes #websecurity