AWS has introduced a new feature for its Network Firewall that allows security teams to track the hit count of stateful firewall rules. This capability helps identify which rules are actively matching traffic, making it easier for teams to spot unused or redundant rules. By enabling this feature by default, AWS aims to assist users in ensuring their security controls are functioning as intended. However, it's important to note that this feature currently only applies to stateful rules and does not support stateless rules. This update has no additional costs beyond standard charges for storing firewall data, making it a beneficial tool for organizations looking to enhance their network security management.
Amazon Web Services (AWS) has introduced a new method to ensure AI agents respect user access controls when retrieving data. This approach allows authorization context to flow through AI agents, meaning that access restrictions are enforced by AWS infrastructure and downstream services rather than relying solely on the AI agent itself. This is particularly important for users of the Amazon Bedrock AgentCore, who can develop AI agents that draw information from various sources like Amazon DynamoDB and internal knowledge bases. Without proper context about the user making a request, AI agents could inadvertently disclose sensitive information. By implementing these controls, AWS aims to enhance data security and prevent unauthorized access, which is crucial for businesses handling sensitive data.
A significant data breach has emerged following the LiteLLM supply chain attack, with a massive 153GB archive of stolen credentials being discovered. This archive, analyzed by Hudson Rock, contains sensitive information from thousands of corporate domains, including major companies like AWS, Samsung, Cisco, and Salesforce. The data includes 433,909 files and over 118,000 CI runner dumps linked to nearly 2,500 corporate domains. Hudson Rock's co-founder stated that they are using this information to inform a global ethical disclosure initiative. The exposure of such extensive credentials poses a serious risk to the affected companies and their customers, as attackers could exploit this data for unauthorized access or other malicious activities.
Researchers from Tracebit have discovered a method called 'context bombing' that can effectively counteract AI hacking attempts. By placing prompt injections alongside sensitive data like passwords and cryptographic keys on Amazon Web Services, attackers can be directed to issue forbidden commands to AI models. When these commands, such as requests for dangerous information or politically sensitive references, are encountered, the AI stops following its original instructions and shuts down. This finding is significant as it offers a new defensive strategy against potential AI-driven attacks, which raises concerns about the misuse of AI technologies. The research suggests that understanding and manipulating AI's guardrails can be a potential avenue for both attackers and defenders in the cybersecurity realm.
ABB Ability Zenon is facing significant vulnerabilities that could allow attackers to bypass security measures, crash systems, and compromise data. The issues primarily affect the IIoT services bundled with MongoDB version 4.2 across all versions of ABB Ability Zenon. Notably, vulnerabilities such as improper handling of length parameters and exploitation of uninitialized memory could lead to unauthorized actions. ABB has recommended urgent remediation steps, including replacing the bundled MongoDB with a supported version and uninstalling IIoT services if they are not needed. Given that these vulnerabilities impact critical infrastructure sectors like energy and healthcare, organizations using ABB Ability Zenon must act quickly to secure their systems.
A recent report reveals that non-human identities, such as automated processes and machines, account for 91% of all activity in production environments. This includes tasks like backup jobs, scanning, and logging, often occurring outside of standard business hours. The research indicates that only 20% of this non-human activity takes place during regular office hours, which raises concerns about security. If attackers gain access to credentials associated with these machine identities, they can operate undetected, posing significant risks to organizations. This situation emphasizes the need for improved credential management and monitoring to prevent unauthorized access and potential breaches.
CareCloud, a health tech company based in New Jersey, has revealed that a data breach has compromised the medical and financial information of 345,000 individuals. The breach occurred in systems hosted on Amazon Web Services (AWS) and involves patient records from over 45,000 healthcare providers across the United States. Although CareCloud first reported the breach back in March, they are now notifying those affected. This incident raises concerns about the security of sensitive health information and the potential risks for identity theft or fraud for the individuals involved. As data breaches become more common in the healthcare sector, it's crucial for companies to strengthen their security measures to protect patient data.
Amazon's threat intelligence team has linked a recent hack of the popular JavaScript library axios to earlier compromises by a North Korean hacking group. They traced domain records from the axios breach back to a lesser-known npm package that was used as a precursor in their attack strategy. This earlier incident highlights the tactics employed by the attackers and raises concerns about the security of open-source software, which many developers rely on for their projects. As more developers use these packages without thorough vetting, they become attractive targets for cybercriminals. Users of axios and related npm packages should be particularly vigilant about security practices to protect their applications from potential vulnerabilities.
A recent study by Aryon Security found that over 3.7 million short-lived cloud resources on AWS are exposed to the public, often containing highly sensitive information. These exposures typically last only a few minutes to hours, which makes them difficult for existing security tools like Cloud Security Posture Management (CSPM) and Cloud Native Application Protection Platforms (CNAPP) to detect. This gap poses a significant risk for organizations using AWS services that allow public sharing, as attackers could easily exploit these misconfigurations within that short window. The findings raise concerns about the limitations of current security practices and the need for proactive measures to protect cloud resources from being inadvertently exposed. Organizations must reassess their security strategies to address these fleeting vulnerabilities effectively.
A newly disclosed vulnerability in the Linux kernel, known as RefluXFS and tracked as CVE-2026-64600, allows unprivileged local users to overwrite files owned by the root user on systems using the XFS filesystem. This flaw, which has been around for nine years, can grant persistent root access to attackers on default installations of Red Hat Enterprise Linux (RHEL), Fedora Server, and Amazon Linux. Researchers from Qualys demonstrated how this vulnerability can be exploited, raising significant concerns for system administrators and users of these platforms. Given the potential for local users to gain elevated privileges, it is crucial for affected organizations to assess their systems and apply necessary mitigations to prevent unauthorized access.
Amazon has introduced a new feature in GuardDuty called the investigation agent, which is currently in public preview. This tool uses artificial intelligence to streamline the initial steps of threat investigations within AWS accounts and organizations, aiming to help security teams save time. During the preview phase, users can access the investigation agent at no additional cost in 10 different AWS Regions, but there are limitations on usage: each account can only run 10 investigations daily and a total of 100 during the preview. It's important to note that failed investigations do not count against these limits. This development could significantly enhance the efficiency of security operations for AWS users by automating routine investigation tasks.
A newly discovered vulnerability in the Shark RV2320EDUS robot vacuum allows attackers to control other Shark vacuums within the same AWS region. By extracting a certificate from the vacuum's flash storage, researchers can execute root commands on other devices, giving them access to features like the vacuum's camera, navigation controls, and even the Wi-Fi password in plaintext. This security flaw was reported by a researcher known as tokay0, who tested the method on a limited number of devices. The implications are significant, as it raises concerns about the security of smart home devices and the potential for unauthorized surveillance and control. Users of affected Shark vacuums should be aware of this vulnerability and take steps to secure their devices until a fix is provided.
The Cybersecurity and Infrastructure Security Agency (CISA) faced a significant data leak after a contractor mistakenly published internal CISA credentials, including AWS Govcloud keys, on a public GitHub repository. This sensitive information was accessible for nearly six months before the leak was brought to light by KrebsOnSecurity. The incident raises serious concerns about the agency's security protocols and response strategies. Experts emphasize the need for improved oversight and better training for contractors to prevent similar occurrences in the future. This leak not only jeopardizes CISA's operations but also sets a concerning precedent for handling sensitive information in the cybersecurity community.
A lone attacker successfully breached a large AWS cloud environment in just 72 hours by exploiting artificial intelligence workflows, taking advantage of cloud vulnerabilities, and using stolen credentials. This incident targeted a significant Amazon customer, resulting in an extortion attempt. The implications are serious, as it showcases how AI can be manipulated for malicious purposes and emphasizes the need for stronger security measures in cloud environments. Organizations using cloud services should be especially vigilant about credential management and vulnerability assessments to prevent similar attacks. This incident serves as a warning for companies relying on cloud infrastructure to enhance their security protocols.
Recent reports have surfaced regarding the use of AI to generate recipes for illicit drugs, including cocaine, which raises serious concerns about the potential for increased drug production and trafficking. Additionally, a Russian hacking group has been implicated in a series of cyberattacks targeting various organizations, showcasing their ongoing efforts to exploit vulnerabilities for espionage and financial gain. Meanwhile, the cybersecurity group known as Scattered Spider has been linked to multiple incidents involving data breaches and ransomware attacks, further complicating the security landscape. Companies like Cisco and Amazon have also found themselves in the spotlight as new vulnerabilities have been identified in their systems, prompting urgent calls for updates and patches to safeguard user data. The combination of these threats emphasizes the need for heightened security measures across industries to protect against both physical and digital dangers.