#AWS
23 stories taggedAWS.

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed
Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

Attackers Are Scanning Exposed Vite Dev Servers to Steal AWS and Azure Keys
A month-long campaign hunted cloud credentials on internet-facing Vite servers using a file-read bypass disclosed in April.

Cloud Security Isn't One Problem. It's Three.
A new Intruder study of 3,000 organisations finds AWS, Azure, and Google Cloud fail in different ways, and one checklist won't catch them all.

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could
Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud
Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

CareCloud tells 3.7 million patients their data was taken in March breach
The healthcare IT firm's SEC filing pointed to an eight-hour outage. The full patient count only landed with regulators months later.

A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities
Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

Researchers Find AI Agents at AWS, Google and Vercel Can Be Tricked Into Running Tools Without the AI
Flaws in agent plumbing let forged instructions reach powerful tools before any safety check runs, and in some cases the AI model never runs at all.

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign
Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

AI Isn't Bringing New Attack Tricks. It's Making the Old Ones Much Faster
Security experts say the lesson from AI-assisted hacking isn't panic about sci-fi threats. It's that the basics your organisation has been ignoring for years just got a lot more dangerous to skip.

OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea
A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division naming state-backed hackers. Stories that almost slipped past.

CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People
A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant
Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

Fake Files That Stop Hackers: How 'Context Bombs' Crash AI Attack Agents
A security firm has found a way to halt automated AI attacks by planting decoy text that triggers the safety rules built into AI systems. In tests, AI-driven attack success rates dropped by up to 90%.