Security News

How Amazon red-teamed Alexa+ to keep your kids from ordering 50 pizzas
2025-05-01 17:09

Will the personal assistant shop for groceries? Or get hijacked by a teen? RSAC If Amazon's Alexa+ works as intended, it could show how an AI assistant helps with everyday tasks like making dinner...

How Amazon red-teamed Alexa+ to keep your kids from ordering 50 pizzas
2025-05-01 17:09

Will the personal assistant shop for groceries? Or get hijacked by a teen? RSAC If Amazon's Alexa+ works as intended, it could show how an AI assistant helps with everyday tasks like making dinner...

Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal
2025-04-08 16:56

Cybersecurity researchers have disclosed details of a now-patched security flaw in the Amazon EC2 Simple Systems Manager (SSM) Agent that, if successfully exploited, could permit an attacker to...

Amazon to kill off local Alexa processing, all voice requests shipped to the cloud
2025-03-17 21:12

Web souk says Echo hardware doesn't have the oomph for next-gen AI anyway Come March 28, those who opted to have their voice commands for Amazon's AI assistant Alexa processed locally on their...

Do You Hear What I Hear? Amazon Removes Echo Privacy Setting — What You Should Know
2025-03-17 17:27

Amazon is mandating cloud-based processing for Echo voice commands, removing local storage and disabling Alexa’s voice ID to expand its generative AI capabilities.

whoAMI attacks give hackers code execution on Amazon EC2 instances
2025-02-13 23:35

Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name. [...]

Delivering Malware Through Abandoned Amazon S3 Buckets
2025-02-12 12:09

Here’s a supply-chain attack just waiting to happen. A group of researchers searched for, and then registered, abandoned Amazon S3 buckets for about $400. These buckets contained software...

Amazon Redshift gets new default settings to prevent data breaches
2025-02-03 21:37

Amazon has announced key security enhancements for Redshift, a popular data warehousing solution, to help prevent data exposures due to misconfigurations and insecure default settings. [...]

Ransomware abuses Amazon AWS feature to encrypt S3 buckets
2025-01-13 15:27

A new ransomware campaign encrypts Amazon S3 buckets using AWS's Server-Side Encryption with Customer Provided Keys (SSE-C) known only to the threat actor, demanding ransoms to receive the...

Android malware found on Amazon Appstore disguised as health app
2024-12-19 18:59

A malicious Android spyware application named 'BMI CalculationVsn' was discovered on the Amazon Appstore, masquerading as a simple health tool but stealing data from infected devices in the...