#awssecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #awssecurity, aggregated by home.social.
-
🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! https://radar.offseq.com/threat/cve-2026-12530-improper-neutralization-of-argument-917f42dfcc3cfd56 #OffSeq #AWSSecurity #Python #CVE2026_12530
-
🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! https://radar.offseq.com/threat/cve-2026-12530-improper-neutralization-of-argument-917f42dfcc3cfd56 #OffSeq #AWSSecurity #Python #CVE2026_12530
-
🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
https://theguptalog.blogspot.com/2026/04/i-bypassed-aws-api-gateway-auth-with.html #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated -
🥳🎉 Congratulations, digital locksmith! You've managed to trick AWS with a trailing slash, earning a whopping $12,000 for adding punctuation like a grammar vigilante. 🧐 Apparently, security now hangs by a thread, or rather, a single character—truly groundbreaking stuff in the world of #fintech babysitting. 🔓💰
https://theguptalog.blogspot.com/2026/04/i-bypassed-aws-api-gateway-auth-with.html #digitallocksmith #AWSsecurity #cybersecurity #punctuationhack #HackerNews #ngated -
Now on Crucial Exams: AWS Certified Security Specialty (SCS-C03) - 250 practice questions and 220 flashcards to help you pass. Start studying: https://crucialexams.com/s/hjqNttCN #AWSSecurity
-
Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.
#crimsoncollective
#awssecurity
#cloudattacks
#databreach
#cyberthreats -
Crimson Collective is using clever tricks on AWS—from sniffing out exposed keys to full-blown privilege escalation. Think your cloud’s safe? Discover how these tactics could put your data at risk and what you can do about it.
#crimsoncollective
#awssecurity
#cloudattacks
#databreach
#cyberthreats -
Some early morning coffee and catching up on the latest AWS IAM news and blogs on my Kindle Scribe - love this big screen! Becoming a bit of a habit (a good one too). #aws #awssecurity
-
Breaching the Data Perimeter: CloudTrail as a mechanism for Data Exfiltration
-
Get the scoop on the latest #AWS shadow resource & S3 Bucket namesquatting attacks in our new 7-minute video! Learn how attackers exploit predictable naming to compromise #cloud infrastructure and how to prevent these attacks. https://youtu.be/rc4CHfVxezI
-
New Phishing Campaign Attacking AWS Accounts To Steal Logins https://cybersecuritynews.com/aws-phishing-campaign/ #CybersecurityTrends #CyberSecurityNews #PhishingAttacks #AWSSecurity #Phishing #cloud
-
New Phishing Campaign Attacking AWS Accounts To Steal Logins https://cybersecuritynews.com/aws-phishing-campaign/ #CybersecurityTrends #CyberSecurityNews #PhishingAttacks #AWSSecurity #Phishing #cloud
-
IdentifyMobile incident exposed 200M records from hundreds of companies
https://stackdiary.com/identifymobile-incident-exposed-200m-records-from-hundreds-of-companies/
#Security #DataBreach #IdentifyMobile #SMS #AWS #Cybersecurity #Privacy #Hack #2FA #Authentication #DataProtection #InfoSec #CCC #TechNews #OnlineSecurity #Encryption #DataLeak #Vulnerability #Incident #TechSafety #ConfigurationError #Webex #AWSsecurity #DigitalSecurity #CloudSecurity #DataPrivacy #TechBreach #SecurityFlaw #CyberSafety #DataSecurity
-
TIL, there's a hard coded client_id in the #AWS #awsconsole for what I suspect is an AWS managed account that handles oauth2.0 for root/some login types.
The client_id depending on the service that it first redirects looks like this arn:aws:iam:015428540659:user/s3
Another service that I've noticed is phd-console (Which I think is AWS health dashboard).
So in this pattern it looks like your secret access key is treated as the client secret in an authorization code flow.
The code/access token returned by AWS is an opaque encrypted JWT.
-
A rundown of AWS security best practices. How to tame the cloud and deliver robust cloud services that won't keep you awake at night.
https://www.blackchili.co.uk/aws-best-practices/
#cloudsecurity #awssecurity #keepitsimple #getthebasicsright #blackchili
-
🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.
https://www.youtube.com/watch?v=H7C-qUZm8mY
#AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource
-
🔒 Security is of the highest priority for us and our customers. Ensuring the security of their applications running on the underlying infrastructure is crucial. We trust in the key capabilities of AWS to provide a robust security layer, enhanced within our own platform.
https://www.youtube.com/watch?v=H7C-qUZm8mY
#AWS #AWSDevOps #AWSSecurity #Lagoon #Kubernetes #security #infrastructure #ZeroOps #DevOps #OpenSource
-
The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! https://aws.amazon.com/blogs/security/gain-insights-and-knowledge-at-aws-reinforce-2023/ #awssecurity #awscloud
-
The #AWSreInforce registration is now open! What to expect: In-depth content across 6 tracks, hands-on learning opportunities & networking with leaders & experts in the industry. I look forward to seeing you in Anaheim, June 13-14! https://aws.amazon.com/blogs/security/gain-insights-and-knowledge-at-aws-reinforce-2023/ #awssecurity #awscloud
-
#ChatGPT explaining cross-account Security Group referencing pretty neatly. One of the easiest ways to implement an IP Address-free trust between connected apps in #AWS.
Also called #microsegmentation.
FOLLOW US as we explore cloud network security with #AI.
-
We ask #ChatGPT about an oft overlooked policy that you should be putting in place when using #VPC #Endpoints in #AWS. Do NOT inadvertently allow access to other tenants' resources!
FOLLOW US as we explore cloud network security with #AI.
-
AWS Elastic Container Registry Public (ECR Public) vulnerability:
=>Hackers can delete, update, and create ECR Public images, layers, and tags in registries and repositories that belong to victims' AWS Accounts
https://blog.lightspin.io/aws-ecr-public-vulnerability
Credit: @gafnitav @LightspinTech
#infosec #AwsSecurity #ContainerSecurity #Devops #DevSecops #kubernetes #websecurity