Saturday, 21 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Colocation > Critical AWS Vulnerabilities Allow S3 Attack Bonanza
Colocation

Critical AWS Vulnerabilities Allow S3 Attack Bonanza

Last updated: August 12, 2024 11:17 am
Published August 12, 2024
Share
Critical AWS Vulnerabilities Allow S3 Attack Bonanza
SHARE

Six crucial vulnerabilities in Amazon Internet Companies (AWS) may have allowed risk actors to focus on organizations with distant code execution (RCE), exfiltration, denial-of-service assaults, and even account takeovers.

“Many of the vulnerabilities had been thought-about crucial as a result of they gave entry to different accounts with minimal effort from the attacker perspective,” Aqua’s lead safety researcher Yakir Kadkoda tells Darkish Studying.

Throughout a briefing on August 7 at Black Hat USA in Las Vegas, researchers at Aqua Safety revealed that they found new assault vectors utilizing bugs “Bucket Monopoly” and “Shadow Assets.” The impacted AWS companies embody Cloud Formation, CodeStar, EMR, Glue, SageMaker, and Service Catalog.

Upon discovering the vulnerabilities in February, the Aqua researchers reported them to AWS, which confirmed the problems and rolled out mitigations to the respective companies piecemeal between March and June. Nonetheless, open supply iterations may nonetheless be weak.

‘Bucket Monopoly’: Attacking Public AWS Account IDs

The researchers first uncovered Bucket Monopoly, an assault technique that may considerably increase the success price of assaults that exploit AWS S3 buckets – i.e., on-line storage containers for managing objects, akin to recordsdata or photographs, and assets required for storing operational information…

Associated:Omdia: AWS Dominated $57B Cloud Storage Companies Market in 2023

Continue reading this article in Dark Reading.



Source link

See also  AWS rolls out new tool to simplify regional cloud planning
TAGGED: attack, AWS, Bonanza, Critical, vulnerabilities
Share This Article
Twitter Email Copy Link Print
Previous Article How the chip giant missed a big opportunity How the chip giant missed a big opportunity
Next Article Assessing the State of Data Center Supply Chains in H2 2024 Assessing the State of Data Center Supply Chains in H2 2024
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Singular, Google resolve AI hardware patent controversy

Singular Computing, a pc {hardware} and software program developer for knowledge facilities and edge computing,…

March 11, 2024

How Cisco builds smart systems for the AI era

Among the many massive gamers in know-how, Cisco is likely one of the sector’s leaders…

February 5, 2026

Tyto Athene Acquires stackArmor

Tyto Athene, a Reston, VA-based federal methods integrator of mission-focused digital transformation options, and portfolio…

May 8, 2025

Prime Security debuts with $6M in funding for AI security by design

Be a part of our every day and weekly newsletters for the most recent updates…

October 13, 2024

Securing digital identity through advanced biometric authentication

CardLab gives passwordless biometric authentication, defending enterprises and demanding infrastructure from evolving cyber threats and…

November 19, 2025

You Might Also Like

Prague, Czechia - 7 23 2024: Smartphone on surface showing OpenAI logo. OpenAI is a non-profit organization for artificial intelligence research.
Global Market

OpenAI’s $50B AWS deal puts its Microsoft alliance to the test

By saad
Submer partners with Hammer Distribution to enhance UK AI infrastructure
Colocation

Submer partners with Hammer Distribution to enhance UK AI infrastructure

By saad
UAE-IX powered by DE-CIX now supports 800 GE access in the Middle East
Colocation

UAE-IX powered by DE-CIX now supports 800 GE access in the Middle East

By saad
Data Center Male Administrator Using Laptop Computer. Maintenance Specialis working in Cloud Computing Facility on Cyber Security and Network Protection. Server Farm Analytics. Medium Wide
Global Market

How AWS is reinventing the telco revenue model

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.