Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > AWS
#AWS

Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace

4 September 2026  |  dark6  |  Cybercrime

A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...

>> read more

28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find

27 August 2026  |  dark6  |  Databreach

A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrubbing...

>> read more

AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation

17 August 2026  |  dark6  |  Vulnerability

Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline...

>> read more

AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time

29 June 2026  |  dark6  |  Phishing

A real-time adversary-in-the-middle phishing kit has been targeting AWS engineers, stealing credentials and MFA codes simultaneously to hijack cloud sessions before they expire. Standard MFA provides zero protection...

>> read more

Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers

26 June 2026  |  dark6  |  Malware

A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...

>> read more

HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic

22 June 2026  |  dark6  |  Cybercrime

Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...

>> read more

TeamPCP Poisons Microsoft’s Official Python DurableTask SDK — Multi-Cloud Credential Worm Hits PyPI

27 May 2026  |  dark6  |  Cybercrime

The TeamPCP threat group has compromised three consecutive versions of Microsoft's official Python DurableTask SDK on PyPI, injecting a worm-like payload that steals multi-cloud credentials from AWS, Azure,...

>> read more

Amazon S3 buckets targeted by new ransomware attacks

13 January 2025  |  securebulletin.com  |  Ransomware

A new wave of ransomware attacks has emerged, targeting Amazon Web Services (AWS) by exploiting its Server-Side Encryption with Customer Provided Keys (SSE-C). This tactic allows threat actors...

>> read more