Tag: Amazon web services

AWS Cloud Development Kit Vulnerability Exposes Users to Potential Account Takeover Risks
News

AWS Cloud Development Kit Vulnerability Exposes Users to Potential Account Takeover Risks

Researchers studying cybersecurity have discovered a vulnerability in the Cloud Development Kit (CDK) of Amazon Web Services (AWS) that, in some situations, might have led to account takeover. According to a study shared with The Hacker News, the implications of this flaw could, in some cases, enable an attacker to obtain administrative access to a target AWS account, leading to a complete account takeover. The project maintainers resolved the bug in CDK version 2.149.0, released in July, after responsible disclosure on June 27, 2024. Using Python, TypeScript, or JavaScript to define cloud application resources and CloudFormation to deliver them read more about AWS Cloud Development Kit Vulnerability Exposes Users to Potential Account Takeover Risks. Get up to date on the late...
EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub
News

EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on GitHub

In an attempt to aid cryptojacking activities, a new continuing campaign known as EleKtra-Leak has focused on exposed identity and access management (IAM) credentials from Amazon Web Services (AWS) inside open GitHub projects. Researchers William Gamazo and Nathaniel Quist of Palo Alto Networks Unit 42 said in a technical report shared with The Hacker News that "as a result of this, the threat actor associated with the campaign was able to create multiple AWS Elastic Compute (EC2) instances that they used for wide-ranging and long-lasting cryptojacking operations." Operating since December 2020 at the latest, the operation's goal is to mine Monero from up to 474 distinct Amazon EC2 instances between read more EleKtra-Leak Cryptojacking Attacks Exploit AWS IAM Credentials Exposed on ...
Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations
News

Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations

An Indonesian threat actor with financial motivations has been seen using Elastic Compute Cloud (EC2) instances from Amazon Web Services (AWS) to conduct unauthorized crypto mining operations. The gang was initially identified by cloud security firm Permiso P0 Labs in November 2021, and it was given the name GUI-vil (pronounceable as Goo-ee-vil). The company stated in a report published with The Hacker News that "the group displays a preference for Graphical User Interface (GUI) tools, specifically S3 Browser (version 9.5.5) for their initial operations." "Once they have access to the AWS Console, they perform all of their operations directly through the web browser read more Indonesian Cybercriminals Exploit AWS for Profitable Crypto Mining Operations. With ReconBee.com Stay ahe...