Security News

whoAMI attacks give hackers code execution on Amazon EC2 instances
2025-02-13 23:35

Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name. [...]

Delivering Malware Through Abandoned Amazon S3 Buckets
2025-02-12 12:09

Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software...

Amazon Redshift gets new default settings to prevent data breaches
2025-02-03 21:37

Amazon has announced key security enhancements for Redshift, a popular data warehousing solution, to help prevent data exposures due to misconfigurations and insecure default settings. [...]

Ransomware abuses Amazon AWS feature to encrypt S3 buckets
2025-01-13 15:27

A new ransomware campaign encrypts Amazon S3 buckets using AWS's Server-Side Encryption with Customer Provided Keys (SSE-C) known only to the threat actor, demanding ransoms to receive the...

Android malware found on Amazon Appstore disguised as health app
2024-12-19 18:59

A malicious Android spyware application named 'BMI CalculationVsn' was discovered on the Amazon Appstore, masquerading as a simple health tool but stealing data from infected devices in the...

Amazon and Audible flooded with 'forex trading' and warez listings
2024-11-20 13:47

Amazon, Amazon Music, and Audible, an Amazon-owned online audiobook and podcast service, have been flooded with bogus listings that push dubious "forex trading" sites, Telegram channels, and...

Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leaked
2024-11-17 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039) November 2024 Patch...

Amazon confirms employee data exposed in leak linked to MOVEit vulnerability
2024-11-12 13:29

Over 5 million records from 25 organizations posted to black hat forum Amazon employees' data is part of a stolen trove posted to a cybercrime forum linked to last year's MOVEit vulnerability.…

Massive troves of Amazon, HSBC employee data leaked
2024-11-12 10:15

A threat actor who goes by the online moniker “Nam3L3ss” has leaked employee data belonging to a number of corporations – including Amazon, 3M, HSBC and HP – ostensibly compromised during the May...

Amazon confirms employee data breach after vendor hack
2024-11-11 19:10

Amazon confirmed a data breach involving employee information after data allegedly stolen during the May 2023 MOVEit attacks was leaked on a hacking forum. [...]