logo

Delivering Malware Through Abandoned Amazon S3 Buckets

ID: 1d7f8c0d-aa3b-53f1-967f-a05fed370ac8

STIX ID: report--1d7f8c0d-aa3b-53f1-967f-a05fed370ac8

Feed Name: Schneier on Security

Threat Score
75/100

Date Published: 2025-02-12

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

Researchers discovered and registered roughly 150 abandoned Amazon S3 buckets that had been used to host software libraries and update artifacts; after registration the buckets received about 8 million requests over two months, illustrating a high-risk supply-chain vulnerability where attackers could swap in malicious code to be pulled into builds and updates while victims lose the ability to patch or identify affected installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.