logo

Aqua Security Researchers Disclose Series of AWS Flaws

ID: 5788699b-9690-5cd7-9a05-f474e24d6c5a

STIX ID: report--5788699b-9690-5cd7-9a05-f474e24d6c5a

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2024-08-09

Date Updated: 2026-04-22

Author: Michael Vizard

...
...

Aqua Security presented research at Black Hat USA 2024 revealing six vulnerabilities across multiple AWS services that relied on predictable S3 bucket naming. Researchers showed how attackers could pre-create those buckets (“Bucket Monopoly”), store malicious code, and cause targeted organizations to execute that code when enabling a service in a new region—potentially leading to RCE, administrative account creation, data exposure/exfiltration, and denial-of-service. AWS has patched the issues and reported no customer action required or evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.