logo

A simple CodeBuild flaw put every AWS environment at risk – and pwned 'the central nervous system of the cloud'

ID: 7a849cc5-d324-5e9b-84b3-91d67899b64f

STIX ID: report--7a849cc5-d324-5e9b-84b3-91d67899b64f

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-01-15

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Wiz researchers disclosed a critical CodeBuild misconfiguration (CodeBreach) in AWS where unanchored regex ACTOR_ID filters allowed an attacker to bypass pull-request restrictions, create bot accounts that matched maintainer IDs, and gain admin access to AWS GitHub repositories (including the JS SDK). They demonstrated credential exfiltration and the potential to inject malicious code into widely used SDKs—an impact that could have affected millions of applications and the AWS Console—while AWS fixed the flaw and reported no evidence of exploitation in customer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.