Researchers warn of risks tied to abandoned cloud storage buckets
ID: b1f16d3a-bcd7-5281-9514-c97a6dfd5ce8
STIX ID: report--b1f16d3a-bcd7-5281-9514-c97a6dfd5ce8
Feed Name: The Record from Recorded Future News
watchTowr researchers analyzed roughly 150 abandoned AWS S3 buckets and demonstrated that re-registering those bucket names allowed them to observe over 8 million requests and could enable attackers to serve malicious software updates, backdoored VM images, CloudFormation templates, or remote access tooling to requesting systems across governments, enterprises and security vendors; the report details impacted sectors, examples including .mil-related buckets, AWS and researcher actions to remediate, and recommends preventing re-registration of previously used bucket names and better lifecycle management of cloud resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
