All Tags

    CVE

    12 items across 2 sections

    Comparisons1
    Weekly News11

    Week 2 - Jan 6-12, 2026

    A CVSS 8.4 command injection in AWS's new Kiro IDE lets a crafted project execute code the moment you open it. Client VPN gets simplified onboarding. AWS is named ISG Leader for Sovereign Cloud for the third year running.

    2026-01-06 - 2026-01-12

    Week 9 - Feb 24 - Mar 2, 2026

    Security Hub Extended Plan reaches GA with 14+ partners on day one, the launch most enterprises have been waiting for. LexisNexis loses 2 GB via a misconfigured AWS environment. Three AWS-LC crypto library CVEs land in one drop. VPC Encryption Controls move from preview to paid.

    2026-02-24 - 2026-03-02

    Week 12 - Mar 16-22, 2026

    AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.

    2026-03-16 - 2026-03-22

    Week 23 - June 1-7, 2026

    OpenAI GPT-5.5, GPT-5.4, and Codex reach general availability on Amazon Bedrock under the same governance controls as the rest of AWS. Amazon Cognito adds near-real-time multi-Region replication of identities and credentials, Bedrock AgentCore Identity integrates Secrets Manager, and two new CVEs hit Kiro IDE and Graph Explorer.

    2026-06-01 - 2026-06-07

    Week 24 - June 8-14, 2026

    Four AWS bulletins land in a single week, all in the build and agent toolchain: AgentCore CLI code injection, CDK command injection, s2n-quic memory exhaustion, and a heap double-free in the HTTP client under the C++ and Java SDKs. Meanwhile the Klue breach shows again what stolen OAuth integration tokens are worth.

    2026-06-08 - 2026-06-14

    Week 25 - June 15-21, 2026

    AWS unveils Continuum, a model-agnostic vulnerability lifecycle platform, and at AWS Summit New York pushes Security Agent into threat modeling and pull-request review. AWS WAF starts charging AI bots for content. On the patch side: Kiro IDE, the AgentCore Python SDK, and five containerd CVEs.

    2026-06-15 - 2026-06-21

    Week 26 - June 22-28, 2026

    GuardDuty previews AI-powered investigations, and AWS Sign-In gains resource-based policies plus RCPs that lock console access to expected networks. Researchers deliver a triple hit: Unit 42's universal bucket hijacking, a targeted AWS-console phishing kit that handles MFA, and Wiz's disclosure of an Amazon Q Developer flaw that leaked AWS credentials on repo open.

    2026-06-22 - 2026-06-28

    Week 27 - June 29 - July 5, 2026

    AWS discloses an HTTP/2 body-inspection bypass in WAF rated CVSS 9.8, and a new CitrixBleed-class NetScaler flaw is exploited within 24 hours of its patch. On the launch side: ACM speaks ACME, GuardDuty watches sensitive file modifications, and WAF extends to AgentCore Gateway. Three more toolchain bulletins land on July 1.

    2026-06-29 - 2026-07-05

    Week 28 - July 6-12, 2026

    Sygnia documents a lone actor compromising a global enterprise's AWS estate in under 72 hours with AI-assisted workflows. Wiz finds the same symlink trust flaw in six AI coding assistants. On defense: Security Hub gains internet-facing network scanning and AWS Config adds 191 managed rules.

    2026-07-06 - 2026-07-12

    Week 29 - July 13-19, 2026

    GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.

    2026-07-13 - 2026-07-19

    Week 30 - July 20-26, 2026

    GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.

    2026-07-20 - 2026-07-26

    Need Help with AWS Security?

    Our AWS security experts can help you implement best practices across all these topics.

    Contact Us