Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look 'insignificant'
ID: cb602937-14f8-5394-897b-fba3432196d8
STIX ID: report--cb602937-14f8-5394-897b-fba3432196d8
Feed Name: The Register (Security)
watchTowr Labs identified ~150 abandoned AWS S3 buckets still referenced by software update processes and webpages; by re-registering those bucket names they collected more than eight million requests from governments, Fortune 100/500 firms, banks, universities, and other organizations, demonstrating a trivial supply-chain attack path where attackers could place malicious executables or code and have numerous systems automatically retrieve them. The researchers notified affected parties and AWS, sinkholed the buckets, and recommend cloud providers and customers adopt protections (unique bucket naming, ownership checks, and proper update validation) to prevent reuse-based supply-chain compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
