logo

An AWS Configuration Issue Could Expose Thousands of Web Apps

ID: 19cbfa58-4eed-5ee7-9e39-ffaffc368970

STIX ID: report--19cbfa58-4eed-5ee7-9e39-ffaffc368970

Feed Name: WIRED Security

Threat Score
60/100

Date Published: 2024-08-20

Date Updated: 2026-04-26

Author: Lily Hay Newman

...
...

Researchers from Miggo disclosed an AWS Application Load Balancer (ALB) authentication implementation issue where attackers who set up their own ALB and manipulate configuration could make tokens appear to originate from a target's authentication service and have AWS sign them, potentially enabling unauthorized access and data exfiltration; Miggo estimates over 15,000 publicly reachable apps may be vulnerable, though AWS disputes that figure and has updated documentation to recommend claim validation and restricting traffic to customers' own ALBs via security groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.