daily cyber × ai intelligence

index

tagged

[aws]

7 editions · 8 items

September 16, 2026

  • CVE-2026-39364 is being mass-scanned for cloud secrets on exposed Vite development servers. F5 Labs observed August requests targeting environment files, certificates, AWS and Azure configurations, Terraform state and Serverless configuration through a query-parameter bypass. Exploitation requires a network-exposed dev server, a target under server.fs.allow and a matching server.fs.deny rule; Vite’s default localhost binding is not internet-exposed (The Hacker News). · Vulnerabilities & Exploitation

in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways

September 2, 2026

  • Langflow CVE-2026-0768 (CVSS 9.8) is under active exploitation for unauthenticated Python execution as root, with observed activity focused on harvesting OpenAI and AWS API keys from the low-code AI platform (BleepingComputer). VulnCheck ties the same campaign cluster to exploitation of a critical Rails flaw for credential probing and C2 (The Hacker News). · Exploited in the Wild
  • Fake IT support campaign drops a malicious MSI that sideloads a trojanized DLL via a signed binary, then uses WMI to launch a custom reverse shell tunnelled over localhost:9001 to an AWS API Gateway C2 — legitimate cloud fronting plus signed-binary proxy execution in one chain (Unit 42). · Threat Activity

in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk

August 14, 2026

  • The LiteLLM compromise is far larger than initially reported. New reporting from CloudSEK and Hudson Rock puts the blast radius at ~2,500 organizations — including Nvidia, AWS, and Samsung Electronics — with terabytes of credentials exfiltrated in a ~40-minute window and 434,000 CI/CD pipelines exposed (earlier coverage). Some commenters flagged it as possibly the largest credential compromise on record. (Ars Technica, discussion) · Supply Chain

in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries

July 1, 2026

  • Nextron tracked a threat actor running five concurrent spear-phishing campaigns against European defense and UAV supply-chain targets, all sharing one trick: AWS Cognito unauthenticated identity pools. Payloads (C#, Python, HTA) fetch fresh 15-minute STS credentials at runtime — no static keys to burn — and exfiltrate to attacker S3 buckets signed with hand-rolled SigV4. IOCs and detection rules published. Nextron (X) · Cloud & Identity

in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread