-
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In August 2026, automated threat activity targeting exposed Vite development servers increased significantly. Attackers aimed to extract cloud credentials, environment files, and infrastructure state data by exploiting a critical file-read vulnerabilit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking. FortiGuard Labs reported an incident involving Amazon Bedrock in which a leaked, long-lived AWS IAM access…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts by attackers to compromise the most privileged identities in cloud environments. The campaign ran …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often individual stateful firewall rules match live network traffic. This feature aims to minimize relian…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed, often within minutes. These short-lived misconfigurations can include Amazon RDS and DocumentDB sn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An AI-assisted threat actor has demonstrated how quickly a modern AWS environment can be compromised when valid credentials, weak identity controls, and exposed secrets intersect. In about 72 hours, they achieved broad cloud control using familiar tech…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
HazyBeacon is a stealthy cloud-native malware campaign identified as CL-STA-1020. It is exploiting Amazon Web Services (AWS) Lambda Function URLs to create covert command-and-control (C2) channels, marking a significant evolution in attacker tactics. A…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AWS has introduced “Continuum,” a new security capability designed to detect, validate, and remediate code vulnerabilities at machine speed, signaling a shift away from traditional telemetry-heavy security models toward automated, context-driven remedi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


