Aqua Security Researchers Disclose Series of AWS Flaws
ID: 5788699b-9690-5cd7-9a05-f474e24d6c5a
STIX ID: report--5788699b-9690-5cd7-9a05-f474e24d6c5a
Feed Name: Security Boulevard
Aqua Security presented research at Black Hat USA 2024 revealing six vulnerabilities across multiple AWS services that relied on predictable S3 bucket naming. Researchers showed how attackers could pre-create those buckets (“Bucket Monopoly”), store malicious code, and cause targeted organizations to execute that code when enabling a service in a new region—potentially leading to RCE, administrative account creation, data exposure/exfiltration, and denial-of-service. AWS has patched the issues and reported no customer action required or evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
