Critical AWS Vulnerabilities Allow S3 Attack Bonanza
ID: 39184433-cdf9-5bdc-b8fe-577ae01f6e72
STIX ID: report--39184433-cdf9-5bdc-b8fe-577ae01f6e72
Feed Name: Dark Reading
Date Published: 2024-08-08
Date Updated: 2026-04-21
Author: Jeffrey Schwartz, Contributing Writer
Aqua Security researchers disclosed six critical AWS vulnerabilities, including 'Bucket Monopoly' (predictable public AWS account IDs and S3 bucket naming) and 'Shadow Resources' (resource squatting across regions), which could enable remote code execution, data exfiltration, denial-of-service, or account takeover across services such as CloudFormation, CodeStar, EMR, Glue, SageMaker and Service Catalog; AWS issued mitigations between March and June, but open-source projects using predictable bucket names may remain at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
