<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Amazon Web Services Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Amazon Web Services.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Inside Elastic InfoSec's agentic SOC: When to inline your agent's skills for a 5× cost reduction</title><link>https://elastic.co/security-labs/agentic-soc-token-budget-architecture</link><guid isPermaLink="false">cst-3189</guid><description>Elastic InfoSec compares two architectural approaches for agentic security operations centers: a single agent with a library of skills versus a fleet of specialized agents orchestrated through deterministic workflows. Testing on 36,822 real production investigations shows the specialized agent approach costs $0.69 per alert triage versus $3.42 for the single-agent method, a 5.7x difference at scale. The choice between architectures depends on investigation patterns, team maturity, and whether analysts need flexible on-demand skill loading or deterministic methodologies.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code</title><link>https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html</link><guid isPermaLink="false">cst-2952</guid><description>Intezer and Kodem Security discovered a vulnerability in AWS Kiro, an agentic coding IDE, that allowed hidden text on a web page to trigger configuration file rewrites and arbitrary code execution on a developer's machine without requiring user approval. AWS has released a patch, and the flaw remains unassigned a CVE identifier.</description><pubDate>Tue, 21 Jul 2026 16:06:12 GMT</pubDate></item><item><title>AWS wants GuardDuty to automate the first steps of threat investigations</title><link>https://helpnetsecurity.com/2026/07/21/amazon-guardduty-investigation-agent-on-demand</link><guid isPermaLink="false">cst-2895</guid><description>Amazon Web Services introduced an AI-powered investigation agent for GuardDuty that automates threat investigation workflows. The feature is in public preview at no additional cost, available in 10 AWS regions, with usage limits of 10 investigations per account per day during the preview period.</description><pubDate>Tue, 21 Jul 2026 09:14:25 GMT</pubDate></item><item><title>New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens</title><link>https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html</link><guid isPermaLink="false">cst-2778</guid><description>A Go-based botnet named NadMesh emerged in early July 2024, targeting exposed AI services to harvest AWS keys and Kubernetes tokens. The malware uses Shodan scanning to identify vulnerable instances of tools like ComfyUI, Ollama, and Gradio that are often deployed without adequate firewall protection. The operator's dashboard reportedly tracks over 3,800 unique AWS credentials stolen from these compromised systems.</description><pubDate>Fri, 17 Jul 2026 17:12:23 GMT</pubDate></item><item><title>Amazon fixing bug that billed some AWS customers billions of dollars</title><link>https://techcrunch.com/2026/07/17/amazon-fixing-bug-that-billed-some-aws-customers-billions-of-dollars</link><guid isPermaLink="false">cst-2773</guid><description>Amazon Web Services experienced a billing calculation error that generated inflated bill estimates for some customers, showing charges in the billions of dollars. The company is working to resolve the issue. The error appears to have been temporary and affected bill display rather than actual charges.</description><pubDate>Fri, 17 Jul 2026 15:29:21 GMT</pubDate></item><item><title>The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26</title><link>https://tenable.com/blog/black-hat-2026-swarm-event-build-AI-security-agents</link><guid isPermaLink="false">cst-2687</guid><description>Tenable is hosting Swarm, a collaborative build event at Black Hat 2026 where security practitioners will develop open-source AI agents and tools together. The event aims to address isolated development of agentic AI in security teams by fostering community collaboration on agents, skills, and model context protocol servers to improve collective cyber defenses.</description><pubDate>Thu, 16 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide</title><link>https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html</link><guid isPermaLink="false">cst-2676</guid><description>A researcher disclosed an unpatched vulnerability in Shark RV2320EDUS robot vacuums that allows extracting a certificate from one device to gain root access to other vacuums operating on the same AWS region. An attacker exploiting this flaw could control cameras, movement, access home maps, and retrieve plaintext Wi-Fi passwords from affected devices.</description><pubDate>Thu, 16 Jul 2026 09:23:19 GMT</pubDate></item><item><title>Investigating Persistence Mechanisms in AWS</title><link>https://rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms</link><guid isPermaLink="false">cst-2587</guid><description>This article examines AWS persistence mechanisms that attackers use to maintain long-term access after gaining initial compromise. It details how adversaries create or modify IAM users, add credentials and permissions, and provides detection logic and investigation workflows using CloudTrail logs to identify these hidden footholds. The guidance includes LEQL query examples to hunt for suspicious IAM user creation and modification activity.</description><pubDate>Wed, 15 Jul 2026 13:00:00 GMT</pubDate></item><item><title>AWS retools Security Hub for AI and multicloud threats</title><link>https://helpnetsecurity.com/2026/07/15/aws-security-hub-ai-workload-protection</link><guid isPermaLink="false">cst-2558</guid><description>AWS expanded its Security Hub platform to include AI workload protection capabilities and native monitoring for Microsoft Azure environments, with plans to support additional cloud platforms. The update aims to help organizations contextualize and act on security findings more rapidly across multicloud deployments.</description><pubDate>Wed, 15 Jul 2026 08:56:09 GMT</pubDate></item><item><title>Now, defenders are embracing the prompt injection, too</title><link>https://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too</link><guid isPermaLink="false">cst-2424</guid><description>Researchers from Tracebit discovered that defenders can embed prompt injections into stored secrets on AWS to disable attacking AI agents. By placing specially crafted prompts alongside passwords and cryptographic keys, the LLM encounters instructions that violate its safety guardrails and halts its operation.</description><pubDate>Mon, 13 Jul 2026 15:06:34 GMT</pubDate></item><item><title>Lessons Learned from CISA’s Recent GitHub Leak</title><link>https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak</link><guid isPermaLink="false">cst-2418</guid><description>CISA experienced a six-month exposure of internal credentials, including AWS GovCloud administrative keys, after a contractor published sensitive data to a public GitHub repository in May 2026. The agency's postmortem identified delays in secret rotation, unclear incident reporting channels, and gaps in monitoring public code repositories as contributing factors. CISA has since committed to improving key management practices, establishing clearer reporting procedures, and implementing continuous scanning for exposed secrets.</description><pubDate>Mon, 13 Jul 2026 15:03:28 GMT</pubDate></item><item><title>Why cloud security is mission-critical for federal civilian and defense agencies</title><link>https://tenable.com/blog/fedramp-high-il5-federal-government-cloud-security</link><guid isPermaLink="false">cst-2423</guid><description>Cloud security has become critical for federal civilian and defense agencies as environments grow more complex, shifting from adoption decisions to securing what is already deployed at scale. Modern federal cloud infrastructures featuring multi-cloud architectures, containerized workloads, and AI applications create significant risk gaps that adversaries exploit, including misconfigured storage, overprivileged accounts, and hidden lateral movement paths. Achieving mature zero trust architecture requires deep, real-time visibility across seven pillars (users, devices, applications, data, network, automation, and analytics) to enable continuous operational discipline rather than reactive risk management.</description><pubDate>Mon, 13 Jul 2026 14:00:00 GMT</pubDate></item><item><title>AWS gives its ERP agent deny-by-default rules and a separate identity</title><link>https://helpnetsecurity.com/2026/07/10/aws-agentic-ai-erp-automation</link><guid isPermaLink="false">cst-2305</guid><description>AWS has released enhancements to its ERP agent that include deny-by-default authorization rules and a separate identity mechanism. These improvements aim to address security concerns while allowing the agent to automate exception handling in enterprise resource planning workflows across finance operations.</description><pubDate>Fri, 10 Jul 2026 05:00:52 GMT</pubDate></item><item><title>AWS centralizes access, spending, and governance for Claude</title><link>https://helpnetsecurity.com/2026/07/09/aws-claude-apps-gateway-governance</link><guid isPermaLink="false">cst-2231</guid><description>AWS released Claude apps gateway, a self-hosted control plane that centralizes access, cost tracking, and policy management for Claude Code and Claude Desktop across organizations. The gateway replaces per-developer credentials and manual configuration distribution, and works with both Amazon Bedrock and Claude Platform on AWS.</description><pubDate>Thu, 09 Jul 2026 08:37:07 GMT</pubDate></item><item><title>Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours</title><link>https://darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment</link><guid isPermaLink="false">cst-2195</guid><description>A solo attacker leveraged artificial intelligence workflows, chained multiple cloud misconfigurations, and compromised credentials to breach an Amazon Web Services (AWS) customer environment and conduct extortion within 72 hours. The incident demonstrates how AI tooling combined with cloud security gaps and credential theft can rapidly escalate attacks.</description><pubDate>Wed, 08 Jul 2026 20:32:22 GMT</pubDate></item><item><title>Codenotary launches AI security platform that learns from AI agent behavior</title><link>https://helpnetsecurity.com/2026/07/08/codenotary-launches-ai-security-platform-that-learns-from-ai-agent-behavior</link><guid isPermaLink="false">cst-2145</guid><description>Codenotary released AgentMon 3, an enterprise AI security platform featuring adaptive runtime security policies that evolve by learning from AI agent behavior, workflows, and emerging threats within customer environments. The platform is now available through AWS Marketplace to simplify deployment for AWS-based organizations.</description><pubDate>Wed, 08 Jul 2026 08:33:38 GMT</pubDate></item><item><title>​​What’s new in Microsoft Security: June 2026</title><link>https://microsoft.com/en-us/security/blog/2026/06/30/whats-new-in-microsoft-security-june-2026</link><guid isPermaLink="false">cst-326</guid><description>Microsoft announced security updates for June 2026 including MDASH, a multi-model AI scanning system for discovering and remediating vulnerabilities, extended endpoint protection for local AI agents, and new capabilities for identity backup and recovery. Additional releases include database threat protection for open-source AWS RDS instances and customizable reporting features in Microsoft Purview for data security posture management.</description><pubDate>Tue, 30 Jun 2026 16:00:00 GMT</pubDate></item><item><title>Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)</title><link>https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce</link><guid isPermaLink="false">cst-557</guid><description>Splunk published CVE-2026-20253, a pre-authentication remote code execution vulnerability in the PostgreSQL Sidecar Service with a CVSS score of 9.8. The vulnerability affects Splunk Enterprise version 10 and above, with Splunk Enterprise on AWS being vulnerable by default, while on-premises Windows installations require the sidecar to be explicitly enabled. The researchers analyzed the vulnerable service listening on local ports and confirmed the exposure in default deployments.</description><pubDate>Fri, 12 Jun 2026 20:35:13 GMT</pubDate></item><item><title>Introducing Wiz Cloud Cost: Powering Cost Management and Optimization with Context</title><link>https://wiz.io/blog/introducing-wiz-cloud-cost</link><guid isPermaLink="false">cst-1266</guid><description>Wiz has released a cloud cost management tool that combines cloud and AI cost visibility across AWS, Azure, and GCP environments. The platform aims to help teams identify and eliminate waste to improve spending efficiency.</description><pubDate>Mon, 08 Jun 2026 12:00:00 GMT</pubDate></item><item><title>Lawmakers Demand Answers as CISA Tries to Contain Data Leak</title><link>https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak</link><guid isPermaLink="false">cst-136</guid><description>A CISA contractor intentionally published AWS GovCloud credentials and internal secrets on a public GitHub account in May 2025, exposing plaintext credentials to dozens of agency systems. Congressional lawmakers are demanding answers about the security lapse, as CISA struggles to invalidate the leaked credentials more than a week after GitGuardian first notified the agency. CISA claims no sensitive data was compromised, but security experts note the exposure provided adversaries with information and access pathways to federal networks.</description><pubDate>Fri, 22 May 2026 16:34:24 GMT</pubDate></item><item><title>CISA Admin Leaked AWS GovCloud Keys on Github</title><link>https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github</link><guid isPermaLink="false">cst-138</guid><description>A CISA contractor maintained a public GitHub repository that exposed privileged AWS GovCloud credentials, plaintext passwords, API tokens, and internal system details for several months until security researchers alerted the agency in May. The exposed files included administrative access to cloud infrastructure, credentials to CISA's secure code development environment, and access to internal software repositories, representing significant credential mismanagement and disabled security controls. Security experts characterized the incident as one of the most severe government data leaks in recent history due to the sensitivity of exposed assets and potential for lateral movement attacks.</description><pubDate>Mon, 18 May 2026 20:48:21 GMT</pubDate></item><item><title>PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale</title><link>https://sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale</link><guid isPermaLink="false">cst-606</guid><description>SentinelLABS discovered PCPJack, a credential theft worm that targets exposed cloud infrastructure including Docker, Kubernetes, Redis, and MongoDB, while removing artifacts from the TeamPCP threat actor group. The framework harvests credentials from cloud services, containers, developer tools, and financial applications, then spreads to additional hosts via a dropper script that downloads Python-based modules from attacker-controlled infrastructure. Unlike typical cloud malware, PCPJack does not deploy cryptominers, instead suggesting monetization through credential fraud, spam campaigns, extortion, or resale of stolen access.</description><pubDate>Thu, 07 May 2026 10:00:17 GMT</pubDate></item><item><title>AI-generated hunting leads: The hunt starts before you ask the question</title><link>https://elastic.co/security-labs/proactive-threat-hunting-ai-generated-leads</link><guid isPermaLink="false">cst-624</guid><description>Elastic has developed AI-generated threat hunting leads that automatically identify patterns and anomalies in security telemetry by analyzing contextual entity data rather than waiting for human analysts to form hypotheses. The system uses an entity store that tracks user, host, and service characteristics over time, combining attributes, lifecycle events, behavioral signals, and risk scores to surface suspicious patterns that would be difficult for analysts to discover manually. This approach aims to shift security operations from reactive alerting to proactive, environment-specific threat hunting.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>CI/CD pipeline abuse: the problem no one is watching</title><link>https://elastic.co/security-labs/detecting-cicd-pipeline-abuse-with-llm-augmented-analysis</link><guid isPermaLink="false">cst-630</guid><description>Attackers are increasingly targeting CI/CD pipelines rather than production systems directly, compromising developer credentials and modifying workflow files to exfiltrate secrets at scale. The article details specific attack patterns including the GhostAction campaign (327 users, 3,325 stolen secrets), the Shai-Hulud npm worm (46,000 malicious packages), and automated scanning for misconfigurations like the pull_request_target trigger. A new open-source tool, cicd-abuse-detector, has been released to identify suspicious pipeline modifications across GitHub Actions, GitLab CI, and Azure DevOps using regex patterns and language model analysis.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite</title><link>https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware</link><guid isPermaLink="false">cst-314</guid><description>Google Threat Intelligence identified UNC6692, a previously unknown threat group, conducting a multistage intrusion campaign that combined mass email bombardment, Microsoft Teams social engineering impersonating IT helpdesk staff, and a custom malware suite. The attack chain involved tricking victims into downloading a renamed AutoHotkey binary that deployed SNOWBELT, a malicious Chromium browser extension, with persistence established through scheduled tasks and startup folder shortcuts.</description><pubDate>Thu, 23 Apr 2026 14:00:00 GMT</pubDate></item><item><title>Risky Bulletin: AWS kills bucketsquatting</title><link>https://risky.biz/risky-bulletin-aws-kills-bucketsquatting</link><guid isPermaLink="false">cst-220</guid><description>Amazon Web Services introduced a security feature to mitigate S3 bucket namesquatting attacks, where attackers register expired or deleted buckets with predictable names to intercept traffic and collect sensitive data. The technique, documented since 2019, exploits naming conventions to target organizations whose traffic still routes to abandoned buckets.</description><pubDate>Fri, 20 Mar 2026 02:20:46 GMT</pubDate></item><item><title>Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat</title><link>https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat</link><guid isPermaLink="false">cst-2119</guid><description>LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.</description><pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate></item><item><title>Announcing Pwn2Own Berlin for 2026</title><link>https://thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026</link><guid isPermaLink="false">cst-397</guid><description>Pwn2Own Berlin 2026 will take place May 14-16 with over $1 million in prizes across 31 targets in 10 categories, including newly expanded artificial intelligence categories and increased rewards for Firecracker vulnerabilities. AWS has joined as a co-sponsor, and the competition returns to OffensiveCon after a successful 2025 inaugural event. Registration closes May 7, and the winner will be crowned Master of Pwn with prizes including ZDI reward points, a trophy, and a jacket.</description><pubDate>Thu, 12 Mar 2026 16:25:15 GMT</pubDate></item><item><title>Risky Bulletin: AI-driven hacking campaign breaches 600+ Fortinet devices</title><link>https://risky.biz/risky-bulletin-ai-driven-hacking-campaign-breaches-600-fortinet-devices</link><guid isPermaLink="false">cst-234</guid><description>A Russian-speaking threat actor used commercial AI toolkits to compromise over 600 Fortinet FortiGate firewalls starting in January by targeting exposed management ports protected only by weak passwords without multi-factor authentication (MFA). The campaign did not rely on zero-day or legacy vulnerabilities but instead exploited basic security configuration weaknesses. AWS security researchers documented the campaign and its techniques.</description><pubDate>Mon, 23 Feb 2026 00:51:20 GMT</pubDate></item><item><title>Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity</title><link>https://wiz.io/blog/introducing-ai-cyber-model-arena-a-real-world-benchmark-for-ai-agents-in-cybersec</link><guid isPermaLink="false">cst-1348</guid><description>Wiz Research has created AI Cyber Model Arena, a benchmark that evaluates offensive AI security capabilities across 257 real-world scenarios including zero-day vulnerabilities, CVEs, API and web attacks, and cloud misconfigurations on AWS, Azure, Google Cloud, and Kubernetes. The benchmark measures what AI models and agents can accomplish in practical cybersecurity contexts.</description><pubDate>Thu, 12 Feb 2026 18:05:58 GMT</pubDate></item><item><title>CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild</title><link>https://wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild</link><guid isPermaLink="false">cst-1360</guid><description>Wiz Research identified a critical supply chain vulnerability that exploited a CodeBuild misconfiguration to gain unauthorized access to AWS GitHub repositories, including the one hosting the JavaScript SDK for the AWS Console. The attack demonstrates how misconfigurations in build infrastructure can be leveraged to compromise widely-used software dependencies that impact many downstream users.</description><pubDate>Thu, 15 Jan 2026 15:00:00 GMT</pubDate></item><item><title>Merry Christmas Day! Have a MongoDB security incident.</title><link>https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb?source=rss----8343faddf0ec---4</link><guid isPermaLink="false">cst-587</guid><description>A public exploit for CVE-2025-14847 was released on Christmas Day, enabling unauthenticated memory reads from MongoDB instances. The vulnerability affects all MongoDB versions over the past decade and allows attackers to extract sensitive data such as database passwords and AWS secret keys. With over 200,000 MongoDB instances exposed to the internet and the exploit now publicly available, mass exploitation is expected.</description><pubDate>Fri, 26 Dec 2025 16:52:57 GMT</pubDate></item><item><title>Top AWS re:Invent Announcements for Security Teams in 2025</title><link>https://wiz.io/blog/top-aws-re-invent-announcements-for-security-teams-in-2025</link><guid isPermaLink="false">cst-1375</guid><description>AWS re:Invent 2025 included several announcements relevant to security teams, though the specific technical details were not provided in the source material. Security practitioners should review the full announcements to determine which services and capabilities align with their organization's security posture and operational needs.</description><pubDate>Mon, 08 Dec 2025 21:54:29 GMT</pubDate></item><item><title>Wiz Becomes Fastest Security ISV to Reach $1 Billion in AWS Marketplace Lifetime Sales</title><link>https://wiz.io/blog/1-billion-aws-marketplace-lifetime-sales</link><guid isPermaLink="false">cst-1379</guid><description>Wiz, a cloud security software vendor, has become the fastest independent software vendor to reach $1 billion in lifetime sales through the AWS Marketplace. The achievement reflects customer adoption of the platform and the strength of Wiz's partnership with AWS.</description><pubDate>Tue, 02 Dec 2025 16:55:57 GMT</pubDate></item><item><title>A new type of long-lived key on AWS: Bedrock API keys</title><link>https://wiz.io/blog/a-new-type-of-long-lived-key-on-aws-bedrock-api-keys</link><guid isPermaLink="false">cst-1429</guid><description>AWS has introduced a new type of long-lived API key for Bedrock that simplifies authentication processes. These keys persist over time rather than requiring periodic rotation, which presents both convenience and security tradeoffs for practitioners managing foundation model access.</description><pubDate>Thu, 21 Aug 2025 12:18:13 GMT</pubDate></item><item><title>Wiz MCP Server Now Available in the new AWS Marketplace AI Agents and Tools category</title><link>https://wiz.io/blog/wiz-mcp-server-now-available-in-the-new-aws-marketplace-ai-agents-and-tools-categ</link><guid isPermaLink="false">cst-1446</guid><description>Wiz announced availability of its Model Context Protocol (MCP) server in AWS Marketplace's new AI Agents and Tools category. The MCP server enables users to leverage natural language workflows for security posture improvement and risk remediation.</description><pubDate>Thu, 17 Jul 2025 09:00:01 GMT</pubDate></item><item><title>Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day</title><link>https://greynoise.io/blog/coordinated-cloud-based-scanning-operation-targets-75-known-exposure-points</link><guid isPermaLink="false">cst-1901</guid><description>GreyNoise detected a coordinated reconnaissance campaign on May 8 involving 251 malicious IP addresses hosted on Amazon AWS and geolocated to Japan, targeting 75 known exposure points in a single day. The synchronized nature and infrastructure patterns indicate centralized planning and direction of the scanning activity.</description><pubDate>Tue, 27 May 2025 00:00:00 GMT</pubDate></item><item><title>Deployed on AWS: Wiz and AWS Marketplace</title><link>https://wiz.io/blog/wiz-deployed-on-aws</link><guid isPermaLink="false">cst-1469</guid><description>Wiz has announced its 'Deployed on AWS' status through AWS Marketplace, reflecting an expanded partnership between the two companies. This designation is intended to help customers make informed purchasing decisions about Wiz's cloud security offerings.</description><pubDate>Tue, 06 May 2025 19:06:04 GMT</pubDate></item><item><title>How to use the new CloudTrail network activity events for AWS VPC Endpoints</title><link>https://wiz.io/blog/aws-vpc-endpoint-cloudtrail</link><guid isPermaLink="false">cst-1483</guid><description>AWS has introduced new CloudTrail network activity events that provide visibility into Virtual Private Cloud (VPC) Endpoint traffic. These logs enable security teams to audit endpoint policies, detect anomalous data flows, and investigate potential data exfiltration attempts.</description><pubDate>Thu, 20 Mar 2025 12:00:00 GMT</pubDate></item><item><title>The Basics of AWS Infrastructure Security</title><link>https://wiz.io/blog/aws-infrastructure-security-basics</link><guid isPermaLink="false">cst-1499</guid><description>This article outlines foundational strategies for securing AWS infrastructure, emphasizing layered protection approaches and the shared responsibility model between AWS and customers. It serves as a guide for organizations to improve their overall security posture within Amazon Web Services deployments.</description><pubDate>Thu, 30 Jan 2025 13:00:00 GMT</pubDate></item><item><title>Avoiding mistakes with AWS OIDC integration conditions</title><link>https://wiz.io/blog/avoiding-mistakes-with-aws-oidc-integration-conditions</link><guid isPermaLink="false">cst-1510</guid><description>The article discusses common security mistakes made when integrating OpenID Connect (OIDC) with AWS and how to avoid them. Practitioners working with AWS identity federation should review their OIDC configurations to ensure they are properly secured.</description><pubDate>Wed, 01 Jan 2025 14:00:00 GMT</pubDate></item><item><title>The many ways to obtain credentials in AWS</title><link>https://wiz.io/blog/the-many-ways-to-obtain-credentials-in-aws</link><guid isPermaLink="false">cst-1511</guid><description>A resource explores various methods through which credentials can be obtained in AWS environments, focusing on understanding AWS Identity and Access Management (IAM) credential mechanisms and SDK behaviors. The article emphasizes how defenders can improve their security posture by developing deeper knowledge of these credential procurement vectors and service-specific implementations.</description><pubDate>Fri, 20 Dec 2024 13:00:00 GMT</pubDate></item><item><title>New Developments in LLM Hijacking Activity</title><link>https://wiz.io/blog/jinx-2401-llm-hijacking-aws</link><guid isPermaLink="false">cst-1514</guid><description>A campaign named JINX-2401 is targeting AWS environments using identity and access management (IAM) privilege escalation tactics. The activity involves hijacking large language model (LLM) environments to gain elevated permissions within cloud infrastructure.</description><pubDate>Sun, 15 Dec 2024 14:07:55 GMT</pubDate></item><item><title>Wiz at Re:Invent 2024</title><link>https://wiz.io/blog/recapping-wiz-at-reinvent-2024</link><guid isPermaLink="false">cst-1518</guid><description>Wiz presented updates at Amazon's Re:Invent 2024 conference, highlighting its continued partnership with AWS to help secure customer environments. The announcement emphasizes Wiz's role in the AWS security ecosystem and ongoing collaboration between the two companies.</description><pubDate>Mon, 09 Dec 2024 14:06:45 GMT</pubDate></item><item><title>How to use AWS Resource Control Policies</title><link>https://wiz.io/blog/how-to-use-aws-resource-control-policies</link><guid isPermaLink="false">cst-1522</guid><description>This article discusses AWS Resource Control Policies as a security and governance tool for organizations using AWS. The piece covers how to implement and leverage these policies to enforce consistent security standards across infrastructure.</description><pubDate>Thu, 28 Nov 2024 05:00:00 GMT</pubDate></item><item><title>Deloitte’s Cyber Cloud Managed Services (CCMS) - Enhance cyber posture with AWS and Wiz</title><link>https://wiz.io/blog/deloitte-cyber-cloud-managed-services-integration</link><guid isPermaLink="false">cst-1524</guid><description>Deloitte has launched Cyber Cloud Managed Services (CCMS), a service powered by Wiz that provides automated security workflows and risk management capabilities for AWS cloud environments. The offering aims to streamline vulnerability identification and remediation across cloud infrastructure.</description><pubDate>Tue, 26 Nov 2024 12:00:00 GMT</pubDate></item><item><title>Introducing new Amazon Q Developer plugin for Wiz</title><link>https://wiz.io/blog/amazon-q-developer-plugin</link><guid isPermaLink="false">cst-1529</guid><description>Wiz has released a new Amazon Q Developer plugin that integrates with Amazon Web Services (AWS) to help customers improve their cloud security posture using generative AI capabilities. The plugin enables AWS and Wiz customers to leverage AI-powered insights within their existing development and security workflows.</description><pubDate>Thu, 14 Nov 2024 12:48:19 GMT</pubDate></item><item><title>Accelerating our commitment to Europe with even more investments</title><link>https://wiz.io/blog/accelerating-our-commitment-to-europe-with-even-more-investments</link><guid isPermaLink="false">cst-1531</guid><description>Wiz announced expanded investments in Europe, including support for Amazon Web Services European Sovereign Cloud and establishment of new regional headquarters to serve European customers.</description><pubDate>Wed, 13 Nov 2024 15:00:00 GMT</pubDate></item><item><title>Wiz Expands Runtime Protection to Serverless Containers</title><link>https://wiz.io/blog/wiz-expands-runtime-protection-to-serverless-containers</link><guid isPermaLink="false">cst-1538</guid><description>Wiz has expanded its runtime protection capabilities to cover serverless container environments, adding support for AWS Fargate and Azure Container Apps. The extension provides visibility, blocking, and threat hunting features for these managed container platforms.</description><pubDate>Mon, 28 Oct 2024 14:00:00 GMT</pubDate></item><item><title>AWS Account Vending</title><link>https://wiz.io/blog/scaling-aws-account-management-from-landing-zones-to-account-vending</link><guid isPermaLink="false">cst-1543</guid><description>AWS account vending and landing zones are two distinct strategies for provisioning and managing cloud environments. Account vending focuses on automated deployment of pre-configured accounts to users or teams, while a landing zone provides a foundational architectural framework for multi-account governance. Understanding the differences helps organizations choose the right approach for their account management and operational needs.</description><pubDate>Thu, 10 Oct 2024 14:00:00 GMT</pubDate></item></channel></rss>