Tag

#AWS

23 stories taggedAWS.

Illustration: a physical combination lock left open
AI Security

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed

Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

5 min read
A web browser showing a Vite development server directory listing exposed online, AWS and Azure credential strings visible in configuration files, scanner outpu
Vulnerabilities

Attackers Are Scanning Exposed Vite Dev Servers to Steal AWS and Azure Keys

A month-long campaign hunted cloud credentials on internet-facing Vite servers using a file-read bypass disclosed in April.

3 min read
A split-screen dashboard comparison showing three different cloud provider interfaces (AWS, Azure, Google Cloud) with different security warnings and vulnerabil
Cloud Security

Cloud Security Isn't One Problem. It's Three.

A new Intruder study of 3,000 organisations finds AWS, Azure, and Google Cloud fail in different ways, and one checklist won't catch them all.

3 min read
A cloud security dashboard rapidly cycling through thousands of failed login attempts and vulnerability scans, progress bars filling at inhuman speed, red alert
Cloud Security

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could

Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

4 min read
A security researcher's workstation displaying a spreadsheet with thousands of rows of tracked AWS credentials, with expiration dates and access levels highligh
Cloud Security

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud

Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

4 min read
A healthcare IT office with incident response team members reviewing patient data logs on screens, SEC filing documents and regulatory notifications stacked on
Breaches

CareCloud tells 3.7 million patients their data was taken in March breach

The healthcare IT firm's SEC filing pointed to an eight-hour outage. The full patient count only landed with regulators months later.

4 min read
An office building at dusk with windows lit from within, a laptop on a nearby desk displaying exposed database files, representing the moment when exposed crede
Cloud Security

A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities

Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

3 min read
A network diagram displayed on a monitor with cloud infrastructure icons and security layers, showing a single credential point glowing red as lines of compromi
Cloud Security

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call

A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

4 min read
Cloud service provider architecture displayed on a monitor with AI agent systems connected to external tools, showing forged instruction packets bypassing safet
AI Security

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI

Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

4 min read
A smartphone screen showing a fake Amazon login page overlaid with warning symbols and a map showing geographic origin points of the attack campaign
Threat Intelligence

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign

Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

4 min read
A timeline visualization showing traditional hacking techniques accelerating dramatically with AI assistance, basic network vulnerabilities being exploited at r
AI Security

AI Isn't Bringing New Attack Tricks. It's Making the Old Ones Much Faster

Security experts say the lesson from AI-assisted hacking isn't panic about sci-fi threats. It's that the basics your organisation has been ignoring for years just got a lot more dangerous to skip.

5 min read
Illustration: A split-screen
Breaches

OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea

A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division naming state-backed hackers. Stories that almost slipped past.

3 min read
A cloud storage interface on a computer screen with folders containing medical documents and financial spreadsheets, with a data breach warning notification ove
Breaches

CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People

A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

3 min read
Illustration: a darkened developer workstation with two glowing monitors
AI Security

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant

Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

3 min read
A cybersecurity laboratory with researchers monitoring automated AI-driven attack attempts against systems protected with context bomb decoys, showing attack th
AI Security

Fake Files That Stop Hackers: How 'Context Bombs' Crash AI Attack Agents

A security firm has found a way to halt automated AI attacks by planting decoy text that triggers the safety rules built into AI systems. In tests, AI-driven attack success rates dropped by up to 90%.

4 min read
© 2026 Threat Vectr