#AWS
20 stories taggedAWS.

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud
Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

CareCloud tells 3.7 million patients their data was taken in March breach
The healthcare IT firm's SEC filing pointed to an eight-hour outage. The full patient count only landed with regulators months later.

A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities
Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI
Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign
Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

AI Isn't Bringing New Attack Tricks. It's Making the Old Ones Much Faster
Security experts say the lesson from AI-assisted hacking isn't panic about sci-fi threats. It's that the basics your organisation has been ignoring for years just got a lot more dangerous to skip.

OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea
A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division calling out state-backed hackers. A busy week of stories that almost slipped past.

CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People
A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant
Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

Fake Files That Stop Hackers: How 'Context Bombs' Crash AI Attack Agents
A security firm has found a way to halt automated AI attacks in their tracks by planting decoy text that triggers the safety rules built into AI systems. Success rates for AI-driven hacks dropped by up to 90% in tests.

NadMesh Botnet Is Quietly Raiding Unprotected AI Servers for Cloud Keys
A new Go-based botnet is scanning the internet for popular AI tools left exposed online, and its own dashboard brags about nearly 4,000 stolen Amazon cloud keys.

One Hacked Shark Robot Vacuum Can Hand an Attacker the Keys to Every Shark Vacuum in the Region
A researcher pulled a security key off a $500 robot vacuum and used it to run commands on other people's Shark vacuums, including reading their Wi-Fi passwords in plaintext.

AI Is Making Rich Organisations Even Safer. What Happens to Everyone Else?
A growing body of security leaders says artificial intelligence is deepening a divide that has existed for years between well-resourced organisations and those just trying to keep the lights on.

Cryptomining attack on an AI gateway reveals a much bigger cloud security problem
Hackers broke into an Amazon cloud server acting as a doorway to AI services, planted mining software, and probed for wider access. The real worry is how much power these AI gateways hold.