2 items across 1 section
A quiet week for feature launches turns into a busy one for patching: AWS ships four security bulletins in 48 hours, three touching OpenSearch (authorization bypass, SSRF, and a SQL grammar bypass) and one an out-of-bounds Base64 decoder bug in the AWS SDK for C++.
Truffle Security reports that more than 9,300 of 10,616 re-tested leaked AWS keys still authenticate, 768 of them with full administrator or root access, some five years after first appearing publicly. Security Hub Extended adds Supply Chain Security as its tenth category. AWS also ships seven security bulletins this week, mostly across OpenSearch Dashboards and FreeRTOS-Kernel.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us