4 items across 1 section
AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.
A Vercel employee had OAuth-trusted Context.ai with their corporate Google account. Lumma Stealer hit Context.ai. The attacker walked from Google Workspace into Vercel and read non-sensitive environment variables. Also this week: Vect ransomware lists Trivy/LiteLLM victims, AWS patches EFS CSI and Encryption SDK for Python.
GuardDuty extends threat detection to Bedrock and SageMaker workloads, Security Hub goes multicloud with Azure support and an AI asset inventory, and Cognito removes the last big migration blocker by importing password hashes. Seven AWS bulletins land in four days, including a prompt-and-response leak in AgentCore telemetry.
GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us