Sunday, 8 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Colocation > Critical AWS Vulnerabilities Allow S3 Attack Bonanza
Colocation

Critical AWS Vulnerabilities Allow S3 Attack Bonanza

Last updated: August 12, 2024 11:17 am
Published August 12, 2024
Share
Critical AWS Vulnerabilities Allow S3 Attack Bonanza
SHARE

Six crucial vulnerabilities in Amazon Internet Companies (AWS) may have allowed risk actors to focus on organizations with distant code execution (RCE), exfiltration, denial-of-service assaults, and even account takeovers.

“Many of the vulnerabilities had been thought-about crucial as a result of they gave entry to different accounts with minimal effort from the attacker perspective,” Aqua’s lead safety researcher Yakir Kadkoda tells Darkish Studying.

Throughout a briefing on August 7 at Black Hat USA in Las Vegas, researchers at Aqua Safety revealed that they found new assault vectors utilizing bugs “Bucket Monopoly” and “Shadow Assets.” The impacted AWS companies embody Cloud Formation, CodeStar, EMR, Glue, SageMaker, and Service Catalog.

Upon discovering the vulnerabilities in February, the Aqua researchers reported them to AWS, which confirmed the problems and rolled out mitigations to the respective companies piecemeal between March and June. Nonetheless, open supply iterations may nonetheless be weak.

‘Bucket Monopoly’: Attacking Public AWS Account IDs

The researchers first uncovered Bucket Monopoly, an assault technique that may considerably increase the success price of assaults that exploit AWS S3 buckets – i.e., on-line storage containers for managing objects, akin to recordsdata or photographs, and assets required for storing operational information…

Associated:Omdia: AWS Dominated $57B Cloud Storage Companies Market in 2023

Continue reading this article in Dark Reading.



Source link

See also  PAIX Data Centres forms joint venture with Djibouti Sovereign Fund
TAGGED: attack, AWS, Bonanza, Critical, vulnerabilities
Share This Article
Twitter Email Copy Link Print
Previous Article How the chip giant missed a big opportunity How the chip giant missed a big opportunity
Next Article Assessing the State of Data Center Supply Chains in H2 2024 Assessing the State of Data Center Supply Chains in H2 2024
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

IBM extends serverless computing to GPU workloads for enterprise AI and simulation

The problem of working simulation and high-performance workloads effectively is a continuing problem, requiring enter…

November 4, 2025

Komainu Raises $75M in Series B Funding

Komainu, a St Helier, Jersey-based regulated digital asset providers supplier and custodian, backed by Laser…

January 16, 2025

The benefits of repatriation: Embracing edge computing appliances for VDI in smaller facilities

By Rudi Carolsfeld, Chief Income Officer and Co-founder of Inexperienced Edge Computing Corp As extra…

October 4, 2024

CapeZero Raises $2.6M in Seed Funding

CapeZero, a NYC-based supplier of a software program platform that streamlines monetary workflow for clear…

January 24, 2025

Microsoft unveils safety and security tools for generative AI

Microsoft is including security and safety instruments to Azure AI Studio, the corporate’s cloud-based toolkit…

April 1, 2024

You Might Also Like

Forfusion partners with Stellium Datacenters
Colocation

Forfusion partners with Stellium Datacenters

By saad
container orchestration, clusters, clustering, Kubernetes
Global Market

Four new vulnerabilities found in Ingress NGINX

By saad
AWS logo on wall
Global Market

Amazon confirms 16,000 job cuts, including to AWS

By saad
Nationwide is deepening its use of cloud services with AWS
Cloud Computing

Nationwide is deepening its use of cloud services with AWS

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.