Security News

AWS fixes local file vuln on internal credential access for Relational Database Service
2022-04-12 18:05

A local file read vulnerability in Amazon's Relational Database Service could be exploited to allow an attacker to gain access to internal AWS credentials, the cloud behemoth has confirmed. While no in-the-wild attacks exploited the bug, AWS confirmed it gave researchers access "To internal credentials that were specific to their Aurora cluster."

AWS Lambda sees its first malware attack with Denonia, and we don’t know how it got there
2022-04-08 13:14

AWS secures the underlying Lambda execution environment, yet it is up to the customer to secure the functions. Cado Labs has exposed the first publicly known case of malware specifically designed to run in an AWS Lambda environment.

New malware targets serverless AWS Lambda with cryptominers
2022-04-07 18:58

Security researchers have discovered the first malware specifically developed to target Amazon Web Services Lambda cloud environments with cryptominers. AWS Lambda is a serverless computing platform for running code from hundreds of AWS services and software as a service apps without managing servers.

First Malware Targeting AWS Lambda Serverless Platform Discovered
2022-04-07 18:47

A first-of-its-kind malware targeting Amazon Web Services' Lambda serverless computing platform has been discovered in the wild. Dubbed "Denonia" after the name of the domain it communicates with, "The malware uses newer address resolution techniques for command and control traffic to evade typical detection measures and virtual network access controls," Cado Labs researcher Matt Muir said.

Cryptocurrency-mining AWS Lambda-specific malware spotted
2022-04-07 07:28

Cado Security says it has discovered a strain of malware specifically designed to run in AWS Lambda serverless environments and mine cryptocurrency. While the security firm has only seen the malware running in AWS Lambda, it can be made to run in other Linux-flavored environments, Cado Security CTO and co-founder Chris Doman told The Register this week.

Discover how FortiGate Ensures the Best Protection for your AWS Workloads
2022-04-06 00:00

What is the best way to deliver business continuity in today's rapidly changing environment? You need agile deployments that seamlessly scale and deliver high availability, while maintaining security and ensuring regulatory compliance. To enable your organization to move faster, FortiGate Next Generation Firewall provides AI/ML driven advanced threat protection and scalable VPN connectivity to your AWS workloads.

Top Practices for Managing the Three Levels of AWS Security
2022-04-06 00:00

The nature of the expanding attack surface and advanced threats necessitates broader, more comprehensive protection. Security architects tasked with designing, implementing, and maintaining security for AWS environments should look for comprehensive solutions that deliver multilayer protections which augment native AWS tools.

Best Practices for Managing the Three Levels of AWS Security
2022-04-06 00:00

The nature of the expanding attack surface and advanced threats necessitates broader, more comprehensive protection. Security architects tasked with designing, implementing, and maintaining security for AWS environments should look for comprehensive solutions that deliver multilayer protections which augment native AWS tools.

Top Practices for Managing the 3 Levels of AWS Security
2022-04-06 00:00

The nature of the expanding attack surface and advanced threats necessitates broader, more comprehensive protection. Security architects tasked with designing, implementing, and maintaining security for AWS environments should look for comprehensive solutions that deliver multilayer protections which augment native AWS tools.

Best Practices for Managing the 3 Levels of AWS Security
2022-04-06 00:00

The nature of the expanding attack surface and advanced threats necessitates broader, more comprehensive protection. Security architects tasked with designing, implementing, and maintaining security for AWS environments should look for comprehensive solutions that deliver multilayer protections which augment native AWS tools.