Security News

Legion Malware Upgraded to Target SSH Servers and AWS Credentials
2023-05-24 10:00

An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services credentials associated with DynamoDB and CloudWatch. "This recent update demonstrates a widening of scope, with new capabilities such the ability to compromise SSH servers and retrieve additional AWS-specific credentials from Laravel web applications," Cado Labs researcher Matt Muir said in a report shared with The Hacker News.

Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations
2023-05-22 16:05

A financially motivated threat actor of Indonesian origin has been observed leveraging Amazon Web Services Elastic Compute Cloud instances to carry out illicit crypto mining operations. Cloud security company's Permiso P0 Labs, which first detected the group in November 2021, has assigned it the moniker GUI-vil.

More UK councils caught by Capita's open AWS bucket blunder
2023-05-22 12:13

The bad news train keeps rolling for Capita, with more local British councils surfacing to say their data was put on the line by an unsecured AWS bucket, and, separately, pension clients warning of possible data theft in March's mega breach. Alison Parkin, director of financial services at Derby CC, said Capita supported its council tax and benefits service, and data left exposed was collected in early 2021.

Another security calamity for Capita: An unsecured AWS bucket
2023-05-17 12:48

Capita is facing criticism about its security hygiene on a new front after an Amazon bucket containing benefits data on residents in a south east England city council was left exposed to the public web. Colchester City Council said on Monday it had launched a probe following the discovery of the open bucket, and was working with Capita to fully understand the "Extent of the data spill and take all necessary steps to minimize any impact on residents."

AlienFox Malware Targets API Keys and Secrets from AWS, Google, and Microsoft Cloud Services
2023-03-30 10:08

A new "Comprehensive toolset" called AlienFox is being distributed on Telegram as a way for threat actors to harvest credentials from API keys and secrets from popular cloud service providers. "The spread of AlienFox represents an unreported trend towards attacking more minimal cloud services, unsuitable for crypto mining, in order to enable and expand subsequent campaigns," SentinelOne security researcher Alex Delamotte said in a report shared with The Hacker News.

You just gonna take that AWS? Let Microsoft school your users on cloud security?
2023-03-21 20:43

Given how many organizations now use two or more public clouds - 87 percent of respondents in Flexera's 2023 State of the Cloud report said they have a multicloud strategy - it was important that Microsoft also look outward when talking about security baselines, according to Jim Cheng, senior software engineer at Microsoft. "Today we see that our customers often have to aggregate and reconcile their security management across multiple cloud platforms to meet security and compliance requirements," Cheng wrote in October 2022, when MCSB v1 entered public preview.

Malicious Google ads sneak AWS phishing sites into search results
2023-02-09 18:37

A new phishing campaign targeting Amazon Web Services logins is abusing Google ads to sneak phishing sites into Google Search to steal your login credentials. The malicious Google ads take the victim to a blogger website under the attackers' control, which is a copy of a legitimate vegan food blog.

AWS strains to make Simple Storage Service not so simple to screw up
2022-12-14 21:30

"We want to make sure that you use public buckets and objects as needed, while giving you tools to make sure that you don't make them publicly accessible due to a simple mistake or misunderstanding," the company explained as it introduced Amazon S3 Block Public Access, a way to block public access to S3 buckets through the S3 management console. That's when AWS announced "a couple new features that simplify access management for data stored in Amazon Simple Storage Service."

Amazon ECR Public Gallery flaw could have wiped or poisoned any image
2022-12-13 14:00

A severe security flaw in the Amazon ECR Public Gallery could have allowed attackers to delete any container image or inject malicious code into the images of other AWS accounts.Amazon ECR Public Gallery is a public repository of container images used for sharing ready-to-use applications and popular Linux distributions, such as Nginx, EKS Distro, Amazon Linux, CloudWatch agent, and Datadog agent.

AWS re:Invent 2022: Partners on parade
2022-11-28 15:28

While some AWS partners chose to hold back on their announcements and statements ahead of AWS re:Invent 2022 - presumably in an attempt to vie for share of voice during the event - a handful were vocal in the run-up to this year's show, staged in Las Vegas between Nov. 28 and Dec. 2. How to connect to AWS. Data platform company Redis signed a tighter AWS deal this month to put its Redis Enterprise Cloud real-time data processing capabilities more closely within the global reach of AWS services.