Application Security TeamPCP Moves From OSS to AWS Environments After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities. Ionut ArghireMarch 31, 2026
Cloud Security Iranian Strikes on Amazon Data Centers Highlight Industry’s Vulnerability to Physical Disasters Two AWS data centers in the United Arab Emirates were “directly struck” and another facility in Bahrain was also damaged after a drone landed... Associated PressMarch 3, 2026
Cloud Security AWS Expands Security Hub Into a Cross-Domain Security Platform The AWS Security Hub Extended plan aims to reduce security tool sprawl by correlating findings across multiple security domains. Kevin TownsendMarch 2, 2026
Network Security Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS Threat actors relying on AI have been exploiting exposed ports and weak credentials to take over FortiGate devices. Ionut ArghireFebruary 23, 2026
Cloud Security re:Invent 2025: AWS and Security Vendors Unveil New Products and Capabilities AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event. Eduard KovacsDecember 3, 2025
Cloud Security AWS Trusted Advisor Tricked Into Showing Unprotected S3 Buckets as Secure AWS has addressed a vulnerability that could have been leveraged to bypass Trusted Advisor’s S3 bucket permissions check. Eduard KovacsAugust 22, 2025
Application Security Abandoned Amazon S3 Buckets Could Have Enabled Attacks Against Governments, Big Firms 150 abandoned Amazon S3 buckets could have been leveraged to deliver malware or backdoors to governments and Fortune companies. Eduard KovacsFebruary 5, 2025
Ransomware Compromised AWS Keys Abused in Codefinger Ransomware Attacks A ransomware group tracked as Codefinger is using compromised AWS keys to encrypt S3 bucket data using SSE-C. Ionut ArghireJanuary 14, 2025
Cloud Security AWS Launches Incident Response Service AWS has launched Security Incident Response, a new service for quick and efficient security event management. Ionut ArghireDecember 2, 2024
Phishing AWS Seizes Domains Used by Russia’s APT29 AWS announced the seizure of domains used by Russian hacker group APT29 in phishing attacks targeting Ukraine and other countries. Eduard KovacsOctober 25, 2024
Cloud Security Thousands of Apps Using AWS ALB Exposed to Attacks Due to Configuration Issue As many as 15,000 applications using AWS Application Load Balancer (ALB) could be exposed to ALBeast attacks. Eduard KovacsAugust 21, 2024
Cloud Security Cloud Misconfigurations Expose 110,000 Domains to Extortion in Widespread Campaign Security researchers at Palo Alto Networks discover a threat actor extorting organizations after compromising their cloud environments using inadvertently exposed environment variables. Ionut ArghireAugust 16, 2024
Cloud Security AWS Patches Vulnerabilities Potentially Allowing Account Takeovers AWS has patched vulnerabilities in several products, including flaws that could have been exploited to take over accounts. Eduard KovacsAugust 8, 2024
Artificial Intelligence AWS Deploying ‘Mithra’ Neural Network to Predict and Block Malicious Domains AWS says a massive neural network graph model with 3.5 billion nodes and 48 billion edges is speeding up the prediction and detection of... Ryan NaraineAugust 5, 2024
Cloud Security AWS Announces Authentication and Malware Protection Enhancements AWS announced passkey MFA for IAM and root users, IAM Access Analyzer updates, and Amazon GuardDuty Malware Protection for S3. Eduard KovacsJune 13, 2024
Cloud Security Inside AWS’s Crusade Against IP Spoofing and DDoS Attacks SecurityWeek speaks to Tom Scholl, VP and distinguished engineer at AWS, on how the organization tackles IP Spoofing and DDoS attacks. Kevin TownsendApril 11, 2024
Cybercrime Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services The tool, called FBot, is capable of credential harvesting for spamming attacks, and AWS, PayPal and SaaS account hijacking. Ryan NaraineJanuary 11, 2024
Cloud Security Amazon One Enterprise Enables Palm-Based Access to Physical Locations, Digital Assets AWS announces Amazon One Enterprise, a palm-based identity service that enables users to easily access physical locations and digital assets. Eduard KovacsNovember 28, 2023
Cloud Security AWS Using MadPot Decoy System to Disrupt APTs, Botnets AWS says an internal threat intel decoy system called MadPot has successfully trapped nation state-backed APTs like Volt Typhoon and Sandworm. Ryan NaraineSeptember 29, 2023