3 items across 2 sections
A Vercel employee had OAuth-trusted Context.ai with their corporate Google account. Lumma Stealer hit Context.ai. The attacker walked from Google Workspace into Vercel and read non-sensitive environment variables. Also this week: Vect ransomware lists Trivy/LiteLLM victims, AWS patches EFS CSI and Encryption SDK for Python.
Four AWS bulletins land in a single week, all in the build and agent toolchain: AgentCore CLI code injection, CDK command injection, s2n-quic memory exhaustion, and a heap double-free in the HTTP client under the C++ and Java SDKs. Meanwhile the Klue breach shows again what stolen OAuth integration tokens are worth.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us