-
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In August 2026, automated threat activity targeting exposed Vite development servers increased significantly. Attackers aimed to extract cloud credentials, environment files, and infrastructure state data by exploiting a critical file-read vulnerabilit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking. FortiGuard Labs reported an incident involving Amazon Bedrock in which a leaked, long-lived AWS IAM access…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are using a layered fake IT-support campaign to obtain remote access, deploy a malicious MSI package and conceal hands-on-keyboard activity behind legitimate signed applications and AWS API Gateway infrastructure. The operation demonstrat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts by attackers to compromise the most privileged identities in cloud environments. The campaign ran …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a basic web server misconfiguration can turn source code history into an i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often individual stateful firewall rules match live network traffic. This feature aims to minimize relian…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed, often within minutes. These short-lived misconfigurations can include Amazon RDS and DocumentDB sn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


