Friday, 10 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Colocation > Critical AWS Vulnerabilities Allow S3 Attack Bonanza
Colocation

Critical AWS Vulnerabilities Allow S3 Attack Bonanza

Last updated: August 12, 2024 11:17 am
Published August 12, 2024
Share
Critical AWS Vulnerabilities Allow S3 Attack Bonanza
SHARE

Six crucial vulnerabilities in Amazon Internet Companies (AWS) may have allowed risk actors to focus on organizations with distant code execution (RCE), exfiltration, denial-of-service assaults, and even account takeovers.

“Many of the vulnerabilities had been thought-about crucial as a result of they gave entry to different accounts with minimal effort from the attacker perspective,” Aqua’s lead safety researcher Yakir Kadkoda tells Darkish Studying.

Throughout a briefing on August 7 at Black Hat USA in Las Vegas, researchers at Aqua Safety revealed that they found new assault vectors utilizing bugs “Bucket Monopoly” and “Shadow Assets.” The impacted AWS companies embody Cloud Formation, CodeStar, EMR, Glue, SageMaker, and Service Catalog.

Upon discovering the vulnerabilities in February, the Aqua researchers reported them to AWS, which confirmed the problems and rolled out mitigations to the respective companies piecemeal between March and June. Nonetheless, open supply iterations may nonetheless be weak.

‘Bucket Monopoly’: Attacking Public AWS Account IDs

The researchers first uncovered Bucket Monopoly, an assault technique that may considerably increase the success price of assaults that exploit AWS S3 buckets – i.e., on-line storage containers for managing objects, akin to recordsdata or photographs, and assets required for storing operational information…

Associated:Omdia: AWS Dominated $57B Cloud Storage Companies Market in 2023

Continue reading this article in Dark Reading.



Source link

See also  CoreWeave opens two initial data centres
TAGGED: attack, AWS, Bonanza, Critical, vulnerabilities
Share This Article
Twitter Email Copy Link Print
Previous Article How the chip giant missed a big opportunity How the chip giant missed a big opportunity
Next Article Assessing the State of Data Center Supply Chains in H2 2024 Assessing the State of Data Center Supply Chains in H2 2024
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Kenya Secures Funding for Major Data Center Infrastructure Project | DCN

(The Star, Kenya) -- The Kenyan government has secured a $4.48 billion (Sh682,496,192,000 billion) deal…

January 26, 2024

Has Huawei outsmarted Apple in the AI race?

What was imagined to herald a brand new period of AI for Apple has as…

September 11, 2024

Namada Launches Mainnet, Introducing Shielded Cross-Chain Transactions

Zug, Switzerland, December third, 2024, Chainwire Namada, the shielded asset hub enabling shielded cross-chain transactions,…

December 3, 2024

Google’s Emissions Shot Up 48% Over Five Years Due to AI

(Bloomberg) -- Google’s emissions climbed by virtually half over 5 years, as the corporate has…

July 3, 2024

BNP Paribas introduces AI tool for investment banking

BNP Paribas is testing how far AI might be pushed into the day-to-day mechanics of…

December 21, 2025

You Might Also Like

Anthropic keeps new AI model private after it finds thousands of external vulnerabilities
AI

Anthropic keeps new AI model private after it finds thousands of external vulnerabilities

By saad
Uber expands use of AWS chips for AI workloads
Cloud Computing

Uber expands use of AWS chips for AI workloads

By saad
The European Commission headquarters in Brussels (8)
Global Market

CERT-EU blames Trivy supply chain attack for Europa.eu data breach

By saad
Cisco building exterior with sign
Global Market

Cisco fixes critical IMC auth bypass present in many products

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.