Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > AWS
#AWS

AWS Integration Lambda Could Turn Limited IAM Access Into Privileged Cloud Actions

24 September 2026  |  dark6  |  Vulnerability

CVE-2026-94384 allowed callers of an Amazon Connect Salesforce setup function to make AWS requests with the Lambda execution role's privileges. AWS has fixed the issue in AmazonConnectSalesforceLambda 5.26...

>> read more

Mass Scanning of Exposed Vite Servers Targets AWS and Azure Secrets

15 September 2026  |  dark6  |  Vulnerability

Attackers are automatically probing internet-accessible Vite development servers for environment files, cloud credentials and infrastructure secrets. F5 telemetry recorded about 32,000 raw events in August, highlighting the risk...

>> read more

Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace

4 September 2026  |  dark6  |  Cybercrime

A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...

>> read more

28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find

27 August 2026  |  dark6  |  Databreach

A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrubbing...

>> read more

AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation

17 August 2026  |  dark6  |  Vulnerability

Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline...

>> read more

AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time

29 June 2026  |  dark6  |  Phishing

A real-time adversary-in-the-middle phishing kit has been targeting AWS engineers, stealing credentials and MFA codes simultaneously to hijack cloud sessions before they expire. Standard MFA provides zero protection...

>> read more

Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers

26 June 2026  |  dark6  |  Malware

A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...

>> read more

HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic

22 June 2026  |  dark6  |  Cybercrime

Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...

>> read more