Tag: Amazon Web Services (AWS)

Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts Steal Credentials
News

Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts Steal Credentials

In order to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale, a large-scale credential harvesting operation has been detected using the React2Shell vulnerability as an initial infection vector. The operation has been linked by Cisco Talos to a threat cluster known as UAT-10608. As part of the operation, at least 766 hosts from various cloud providers and geographical locations have been compromised. In a report shared with The Hacker News prior to publication, security researchers Asheer Malhotra and Brandon White stated that UAT-10608 uses automated scripts to extract and exfiltrate credentials from a range of applications, which are then posted to its command-and-control (C2). A w...
Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign
News

Compromised IAM Credentials Power a Large AWS Crypto Mining Campaign

Customers of Amazon Web Services (AWS) have been the subject of an ongoing effort that uses compromised Identity and Access Management (IAM) credentials to facilitate cryptocurrency mining. According to a new report released by the tech giant ahead of publication, the activity, which was initially discovered on November 2, 2025, by Amazon's GuardDuty managed threat detection service and its automated security monitoring systems, uses never-before-seen persistence techniques to impede incident response and continue unhindered. Before deploying cryptocurrency mining resources across ECS and EC2, the threat actor swiftly listed resources and permissions while operating from an external hosting provider, according to Amazon. Crypto miners were up and running within ten minutes of the th...
FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware
News

FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware

It has been noticed that the financially motivated threat actor FIN6 uses phony resumes hosted on Amazon Web Services (AWS) infrastructure to distribute the More_eggs malware family. In a post released with The Hacker News, the DomainTools Investigations (DTI) team stated that the group establishes rapport with recruiters by pretending to be job searchers and striking up conversations on sites like Indeed and LinkedIn before sending phishing messages that result in malware. Golden Chickens, also known as Venom Spider, is another cybercrime gang that is responsible for More_eggs. They were most recently linked to new malware families including TerraStealerV2 and TerraLogger. This JavaScript-based backdoor can facilitate system access, credential theft, and further assaults, such as r...
Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal
News

Amazon EC2 SSM Agent Flaw Patched After Privilege Escalation via Path Traversal

Details of a now-patched security vulnerability in the Amazon EC2 Simple Systems Manager (SSM) Agent have been made public by cybersecurity experts. If exploited successfully, the vulnerability may allow an attacker to execute code and escalate privileges. According to a report shared with The Hacker News, Cymulate stated that the vulnerability could allow an attacker to write files to sensitive areas of the system, execute arbitrary scripts with root privileges, and create directories in unexpected places on the filesystem. Administrators can remotely manage, configure, and run commands on EC2 instances and on-premises servers with the help of Amazon SSM Agent, a feature of Amazon Web Services (AWS). The software executes instructions and actions specified in SSM Documents, whic...
Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail
News

Hackers Exploit AWS Misconfigurations to Launch Phishing Attacks via SES and WorkMail

According to research from Palo Alto Networks Unit 42, threat actors are focusing on Amazon Web Services (AWS) settings in order to distribute phishing attempts to unwary targets. The activity cluster is being monitored by the cybersecurity firm under the moniker TGR-UNK-0011, which stands for a threat group with unclear motive. The company claims that this group overlaps with JavaGhost. Since 2019, TGR-UNK-0011 has been known to be operational. Historically, the organization concentrated on vandalizing websites, according to security expert Margaret Kelley. They switched to sending phishing emails in 2022 in order to make money. It is important to note that these attacks do not take use of any AWS vulnerabilities. Instead, the threat actors use environmental misconfigurations th...
New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution
News

New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution

A new kind of name confusion attack known as whoAMI has been revealed by cybersecurity experts. It enables code execution within an Amazon Web Services (AWS) account for anyone who uploads an Amazon Machine Image (AMI) with a certain name. Seth Art, a researcher at Datadog Security Labs, told The Hacker News that if the assault were carried out on a large scale, it might be used to access thousands of accounts. Numerous open source and private code repositories include the vulnerable pattern. The method essentially consists of uploading a harmful resource and deceiving misconfigured software into using it in place of the genuine counterpart read more about New "whoAMI" Attack Exploits AWS AMI Name Confusion for Remote Code Execution. Get up to date on the latest cybersecurity new...
HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks
News

HTTP/2 Rapid Reset Zero-Day Vulnerability Exploited to Launch Record DDoS Attacks

On Tuesday, Google, Cloudflare, and Amazon Web Services (AWS) announced that they had taken action against unprecedented distributed denial-of-service (DDoS) attacks that were based on a cutting-edge method known as HTTP/2 Rapid Reset. According to a coordinated statement from the firms, the layer 7 assaults were discovered in late August 2023. CVE-2023-44487 is the tracking number for this attack's cumulative susceptibility, and it has a CVSS score of 7.5 out of 10. Attacks on AWS and Cloudflare hit 155 million and 201 million requests per second (RPS), respectively, while attacks against Google's cloud infrastructure peaked at 398 million RPS read more HTTP2 Rapid Reset Zero Day Vulnerability Exploited to Launch Record DDoS Attacks. Stay informed with the best cybersecurity new...