logo

Critical AWS Vulnerabilities Allow S3 Attack Bonanza

ID: 39184433-cdf9-5bdc-b8fe-577ae01f6e72

STIX ID: report--39184433-cdf9-5bdc-b8fe-577ae01f6e72

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-08

Date Updated: 2026-04-21

Author: Jeffrey Schwartz, Contributing Writer

...
...

Aqua Security researchers disclosed six critical AWS vulnerabilities, including 'Bucket Monopoly' (predictable public AWS account IDs and S3 bucket naming) and 'Shadow Resources' (resource squatting across regions), which could enable remote code execution, data exfiltration, denial-of-service, or account takeover across services such as CloudFormation, CodeStar, EMR, Glue, SageMaker and Service Catalog; AWS issued mitigations between March and June, but open-source projects using predictable bucket names may remain at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.