logo

CodeBuild Flaw Put AWS Console Supply Chain At Risk

ID: 0d6d8888-9abf-532f-b1a4-6a858eb5a98a

STIX ID: report--0d6d8888-9abf-532f-b1a4-6a858eb5a98a

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-22

...
...

Wiz Research discovered a critical CodeBuild misconfiguration (an unanchored ACTOR_ID regex) that could let unauthenticated pull requests run privileged builds, exposing GitHub credentials and allowing attackers to inject malicious code into core AWS repositories — notably the AWS SDK for JavaScript used broadly across cloud environments. Wiz demonstrated admin takeover of aws/aws-sdk-js-v3; AWS remediated the flaw within 48 hours, revoked exposed credentials, added build protections, and reported no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.