3 items across 1 section
AWS publishes bulletin 2026-030-AWS, a single rolling document for the Copy.fail / DirtyFrag Linux kernel privilege-escalation class. If you run Amazon Linux, Bottlerocket, ECS, EKS, EMR, Fargate, or SageMaker, this is the bulletin you bookmark. Security Agent meanwhile learns to read whole repositories.
AWS attributes the debug, chalk, and axios npm compromises to North Korea's SAPPHIRE SLEET group, with Wiz data showing roughly 1 in 10 cloud environments hit within a two-hour window. Shield Advanced begins migrating to the WAF Anti-DDoS managed rule group as its default Layer 7 protection. Four new AWS security bulletins land, including an unauthenticated DoS in aws-smithy-json.
JetBrains concludes its investigation into a three-week breach of its Cadence CI/CD service, confirming attackers compromised AWS IAM users and credentials and accessed files in JetBrains-owned S3 buckets, alongside PyCharm source code and user data. Four new AWS security bulletins close the month, and AWS opens beta registration for its new AI Business Strategist certification.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us