Search
Find merged stories by title or summary.
Security updates for Wednesday
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.
Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5. 5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Built for long and complex tasks Opus 5. 5 is designed for codebase migrations, software audits, financial analysis, data collection and workflows involving several applications. Early testers used the model for engineering tasks that ran … More → The post Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI appeared first on Help Net Security .
Need a Nothing phone cheaper? Now's the time to buy
While they might not be a dominant force in the smartphone market, Nothing has managed to stand out from the crowd while still delivering some compelling devices. We've covered a number of its products, and for the most part, they are pretty good. If you've been thinking about picking something new up, we'd highly recommend checking out Amazon's latest sale , with devices starting at $449.
AI agents shall not shop on Amazon: Meta’s Muse joins the ban list - Cybernews
AI agents shall not shop on Amazon: Meta’s Muse joins the ban list Cybernews
AWS Automatically Quarantines Exposed IAM Keys Within 10 Seconds of GitHub Leak
Amazon Web Services can move from detection to containment in seconds when an Identity and Access Management access key appears in a public GitHub repository. In a controlled Unit 42 exposure test, AWS attached its AWSCompromisedKeyQuarantineV3 managed policy to the affected IAM user only 10 seconds after researchers published the credential, sharply reducing the window available for abuse. Long-term IAM access keys remain attractive initial-access vectors because they can provide programmatic access without interactive authentication. Developers may accidentally commit them to source code, configuration files, or publicly accessible environment files. GitHub secret scanning searches public repositories and other public surfaces for recognized credential patterns; through its partner integration, it reports detected AWS secrets directly to AWS so the provider can respond.
Amazon admits Iran drones wiped out AWS cloud data - Cybernews
Amazon admits Iran drones wiped out AWS cloud data Cybernews
Attacker infrastructure, but vibe-coded: tracking the evolution of credential harvesting platforms
In this post, we examine two vibe-coded credential harvesting platforms, Loot and UltraVault, and the Amazon Bedrock abuse used to validate stolen secrets.
Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud . We’re excited to announce the general availability of the first open weight model family, Gemma 4 , on the Amazon Bedrock next-generation inference engine in the AWS European Sovereign Cloud. Gemma 4, released under the Apache 2. 0 license , on Amazon Bedrock benefits from the same data residency and operational controls that define the AWS European Sovereign Cloud so you can build, iterate, and scale generative AI applications while meeting digital sovereignty requirements.
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UAE) region, known as me-central-1. For the UAE, the loss … More → The post Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE appeared first on Help Net Security .
AWS STS simplifies session token size limits and adds session token size monitoring
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session token size in API responses, Amazon CloudWatch metrics, and AWS CloudTrail events. By using STS, you can also generate session tokens of different sizes, so you can find the maximum token size that your infrastructure can support. The 4,096-byte limit is the current maximum, not a permanent ceiling. AWS might increase the limit as new capabilities are added that require session tokens to carry more information. In this post, you learn what has changed, what this change means for you, and what to do next.
Architecting resilient authentication with Amazon Cognito multi-Region replication
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that synchronize user data, manage consistency, and handle failover, all adding significant operational overhead. Amazon Cognito simplifies this with multi-Region replication (MRR) , which automatically replicates user pools across AWS Regions with near-real-time synchronization, built-in failover, and seamless sign-in, while keeping operational complexity and costs optimized.
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The
Search results are sending people to fake Bitrefill checkouts
Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency. The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what appears to be a normal purchase. The fake sites are not operated by or affiliated with Bitrefill; scammers have copied its branding and checkout process. The victim chooses an amount and a cryptocurrency before receiving a QR code and payment address. But instead of paying Bitrefill, they send the cryptocurrency directly to an address controlled by the scammers.
Empowering Open Source Security with Scalable Infrastructure
By Mila Zhou Summary How can open source projects maintain secure infrastructure without financial strain? OpenSSF Premier Member, Amazon Web Services (AWS) addresses this by providing critical funding and scalable compute resources. Through initiatives like the AWS Open Source Promotional Credit Program, maintainers access enterprise-grade security tools and automated testing, ensuring the global software supply chain remains resilient, hardened, and efficient for everyone. Why Does Open Source Security Need Infrastructure Investment? Securing open source software requires more than writing good code. It takes serious compute power to run continuous integration pipelines, fuzzing engines, and secure artifact distribution networks. Infrastructure costs can quickly become a bottleneck for maintainers.
AWS Security Reference Architecture: A deep dive into PCI DSS compliance
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive . This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to PCI DSS have long asked for a comprehensive reference that bridges the gap between general AWS security best practices and the specific technical and organizational controls required to achieve and maintain PCI DSS compliance. This guide answers that need by showing how AWS SRA patterns address PCI DSS intent from account scoping and network segmentation to encryption, logging, and access control. What is the AWS SRA PCI DSS Deep Dive?
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.
Mandiant Founder Kevin Mandia Joins Amazon Board
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek .
🏴☠️ Aurora has just published a new victim : Jinny Beauty Supply
[distributors] Jinny Beauty Supply is one of the largest Korean-American wholesale beauty distributors in the US, operating 9 distribution centers from Doraville, Georgia to Commerce, California. They serve 7,400+ beauty supply stores and 2,800+ international distributors. The exposed material includes: A complete password vault export — 50+ plaintext credentials for PayPal, Braintree, Amazon Seller Central, eBay, Acumatica ERP (production), 12 state tax portals, FedEx, UPS, ShipStation, Microsoft 365, Google Analytics, and internal email. VMware hypervisor root credentials — vCenter and ESXi root passwords giving complete control over the entire virtual infrastructure. 911 scanned credit card authorization forms — full card numbers, CVV, expiry dates, and cardholder signatures for beauty supply store customers across 26 US states.
OSPAR 2026 report now available with 167 services in scope
We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to set out baseline control criteria for outsourced service providers (OSPs) operating in Singapore. These guidelines cover key areas such as cyber hygiene, technology risk management, business continuity, data security, cryptography, and software application development and management, drawing on regulatory direction from the Monetary Authority of Singapore (MAS).
Amazon drops the new Blink Mini 2K Plus to $21.99 with a 45% discount
Save $18 on the Blink Mini 2K Plus, a compact 2K security camera with HDR, infrared night vision, and a 138-degree view.
Apple's home security devices may now launch in 2027
Summarizing existing rumors about Apple launching an AI home security camera, a new report says it will be announced in 2027 alongside a monitoring service. Apple is expected to release a home security system that includes a home hub (left) and cameras such as this HomeKit-compatible Amazon one (right). Apple has not had the best luck so far with security devices, having effectively abandoned HomeKit Secure Routers after few vendors supported it. But it was one of several signs that Apple was aiming at the home with secure devices, and there have long been rumors of a full security system . Now Bloomberg claims to have more details , and a projected launch date. It includes the home security system in a list of products slated for 2027, alongside iPad and MacBook Neo refreshes. Rumor Score: 🤔 Possible Continue Reading on AppleInsider • Discuss on our Forums
OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold
OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. “GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS,” OpenAI said in a statement. Enterprise administrators must manually enable Astra for their workspace, since access is off by default at launch, according to the company. Developers can access Astra in the API as gpt-6-astra or through Amazon Bedrock, OpenAI said, priced at $10 per million input tokens and $50 per million output tokens.
Free streaming boxes may be routing criminal traffic through your home
“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. An earlier report identified CyberFlix TV, available through SuperBox’s custom app store, as containing Popanet proxy functionality that registers the device with a server controlled by the proxy operator. Law enforcement agencies have warned that “foreign entities” are using residential proxies to conceal their identities and make their activity appear to come from someone else’s home network.
Incident response guide for AWS CloudTrail investigations – Part 2
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second part, we explore a more complex, multi-stage attack: how a web application vulnerability can cascade into credential harvesting and unauthorized access to Amazon Bedrock services across multiple AWS Regions. We also cover additional investigation techniques and hardening steps to strengthen your security posture.
Your next smartwatch just dropped to $199, and it lasts nearly two weeks on a charge
Garmin smartwatches are easy to recommend for anyone that's looking for a health and fitness-focused wearable. It might not have the huge app resources that Apple and Wear OS products have, but what it packs is more than enough. We like the Forerunner 165 because it features a sleek and lightweight design, while also offering up to 11 days of battery life . Right now, you can grab the watch for its best price of all time as it drops to $199 from Amazon.
CVE-2026-84851 - Amazon Ion-C Uncontrolled Recursion Denial of Service
CVE ID : CVE-2026-84851 Published : Sept. 2, 2026, 9:05 p. m. • 4 hours, 35 minutes ago Description : An uncontrolled recursion issue exists in Amazon Ion-C versions before 1. 1. 6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. Severity: 7.5 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Managing identity source transition for AWS IAM Identity Center
September 2, 2026 : This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications . You can use IAM Identity Center to create and manage user identities within the Identity Center identity store or to connect to other identity sources. Organizations might need to change their identity source configuration as part of a significant transformation to their identity and access management strategy. Common drivers include switching identity providers (IdPs), consolidating identity infrastructure, adopting new single sign-on capabilities, or migrating off legacy on-premises systems. These transitions require planning.
Agentic security: Detection and response at machine speed
After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep workflows, and make decisions across infrastructure, often without waiting for human approval. Security operations need to keep pace. At Amazon Web Services (AWS) , we believe security should evolve ahead of AI adoption, not behind it. That belief drove our team to collaborate with the SANS Institute on a new chapter in the 2026 Cloud Security Exchange eBook , where we lay out a practical framework for securing agentic workloads at enterprise scale.
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were sent. Kaspersky’s research documented two previously undocumented malware families from the APT group, delivered through fake coding challenges sent to job seekers on LinkedIn. The setup is almost embarrassingly simple once you see it laid out. A fake recruiter contacts a software engineer, offers a role, and sends a coding assessment hosted on a completely legitimate-looking Amazon S3 link, the kind of hosting nobody would think twice about. “During recent threat research, we detected suspicious activity on a system in Afghanistan.
Amazon ad auctions rigged to raise prices, FTC says - cybernews.com
Amazon ad auctions rigged to raise prices, FTC says cybernews.com
Fake IT Support Hackers Abuse Microsoft Teams and Quick Assist to Deploy Reverse Shell
Threat actors are using fake IT support requests on Microsoft Teams to trick employees into granting remote access through Quick Assist, then deploying a multi-stage reverse shell designed to blend into normal Windows activity. Researchers Ofek Lahiani and Raz Rubin reported that the campaign begins with social engineering. Attackers contact targets through external Microsoft Teams chats while posing as IT technicians. They convince victims that a technical problem requires remote support and instruct them to open Microsoft’s legitimate Quick Assist application. Once the victim grants access, the attacker has hands-on control of the device. The operator downloads a malicious MSI installer from an attacker-controlled Amazon S3 bucket and runs it using msiexec. exe . Observed installer names include SE15724BW. msi and KB5094126. msi .
CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline path
CVE ID : CVE-2026-83551 Published : Sept. 1, 2026, 6:11 p. m. • 1 hour, 5 minutes ago Description : Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3. 11. 0 and v2. 256. 0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipeline execution context within the same AWS account. Severity: 8.5 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The new Amazfit Cheetah 2 Pro falls to $399.99 in its first Amazon discount
Amazon cuts 11% off the new Amazfit Cheetah 2 Pro, a premium running watch with dual-band GPS and up to 20-day battery life.
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U. S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9. 5 million people. The company discovered the incident on December 18, 2025, after attackers gained access to part of its Amazon Web Services infrastructure. Aesto Health is a U. S. healthcare technology company based in Birmingham, Alabama. It helps healthcare providers manage and protect electronic health records and other legacy medical data. Its services include secure data migration, electronic health record (EHR) exchanges and long-term data archiving. Aesto works with medical practices and healthcare organizations that need to move, store or access patient information securely.
Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations
Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at the financial sector, making malicious traffic nearly indistinguishable from legitimate business activity. Security researchers describe this as a structural shift toward what some call Trusted Infrastructure Phishing , where every stage of an attack, from delivery to credential theft, runs through legitimate, enterprise-approved services rather than attacker-owned domains. Trusted Cloud Services Abused for Phishing Financial institutions rely heavily on cloud storage, document-sharing tools, and vendor platforms for daily operations, which gives attackers a ready-made attack surface with built-in credibility.
Hackers Use Fake Coding Job Tests to Infect Developers With New Backdoors
Cybersecurity researchers have uncovered a targeted campaign in which hackers use fake software engineering tests to infect developers with previously undocumented remote access trojans (RATs) . The activity has been attributed with high confidence to Mirage Kitten, an advanced persistent threat (APT) group known for targeting organizations in the Middle East and Africa. The campaign abuses legitimate job-search platforms, including LinkedIn, to contact software engineers through fake recruiter profiles. Victims are then directed to download coding challenges hosted on legitimate cloud infrastructure such as Amazon S3. The projects appear to be normal programming assessments but contain hidden malicious components. Researchers identified two malware families, NodeRabbit and PollCat. Both are cross-platform RATs designed to run on Windows, Linux and macOS.
Aesto healthcare data breach impacts 9.5 million people
Healthcare data migration and archiving provider Aesto has disclosed to the US Department of Health and Human Services (HHS) that a data breach announced earlier this year affected 9,540,683 individuals. The incident involved unauthorized access to part of Aesto’s Amazon Web Services (AWS) infrastructure in December 2025 and potentially exposed sensitive patient information, including medical, … The post Aesto healthcare data breach impacts 9.5 million people appeared first on CyberInsider .
OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses
A coalition led by OpenAI is warning that AI will sharply accelerate the speed and scale of cyberattacks, leaving enterprises with a narrowing window to fix long-standing security weaknesses before they are exploited. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the group said in an open letter signed by more than 100 technology and cybersecurity firms, including Microsoft, Google, Amazon Web Services, and Anthropic. “We have a limited window to strengthen cyber defenses.” OpenAI CEO Sam Altman reinforced the urgency in a post on X, calling it a “critically important moment for cyber defense” and warning that there is little time to act.
AI Shopping Assistant Flaws Let Attackers Execute Code on Retailer’s Backend Servers
A newly disclosed report shows how security flaws in an unnamed major US retailer’s AI shopping assistant could be chained from a public mobile app to remote code execution on backend infrastructure. The attack reportedly bypassed multiple protections designed to keep the assistant confined to shopping-related tasks. Rein Security co-founder and CTO Netanel Rubin and researcher Dan Avraham presented the research, titled “Bye Bye AI,” at Black Hat. Their work shows how an AI assistant can serve as a path into enterprise systems when input validation, runtime controls, and application-layer security are applied inconsistently. AI Shopping Assistant Flaws The pair began by fingerprinting five retail assistants: Kroger, Instacart, Amazon Alexa, Walmart Sparky, and Albertsons. Two questions whether the services sold avocados and the unrelated Spanish greeting “¿Cómo estás?”
