logo

Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look 'insignificant'

ID: cb602937-14f8-5394-897b-fba3432196d8

STIX ID: report--cb602937-14f8-5394-897b-fba3432196d8

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-02-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

watchTowr Labs identified ~150 abandoned AWS S3 buckets still referenced by software update processes and webpages; by re-registering those bucket names they collected more than eight million requests from governments, Fortune 100/500 firms, banks, universities, and other organizations, demonstrating a trivial supply-chain attack path where attackers could place malicious executables or code and have numerous systems automatically retrieve them. The researchers notified affected parties and AWS, sinkholed the buckets, and recommend cloud providers and customers adopt protections (unique bucket naming, ownership checks, and proper update validation) to prevent reuse-based supply-chain compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.