11 items across 4 sections
We obtained the actual compromised litellm packages, set up a disposable EC2 instance with honeypot credentials and mitmproxy, and detonated the malware. Full evidence: fork bomb, credential theft in under 2 seconds, IMDS queries, AWS API calls, and C2 exfiltration.
A deep technical breakdown of how threat actor TeamPCP compromised Trivy, pivoted to LiteLLM, and turned a popular AI proxy into a credential-stealing weapon targeting AWS IMDS, Secrets Manager, and Kubernetes.
Enterprise-grade strategies for AWS credential lifecycle management including rotation automation, monitoring, Secrets Manager, and compliance reporting.
Secrets Manager rolls out hybrid post-quantum TLS using ML-KEM, baked into the agent, the Lambda extension, and the CSI driver. Three CVE bulletins land in the same week (QnABot, Ops Wheel, tough/tuftool). AWS finally gives the IAM Service Authorization Reference the deep-dive treatment.
Security Hub learns to find identity risk that no one is using: unused IAM permissions, roles, and credentials, measured against 90 days of real activity. The Extended plan grows to 21 partners across 9 categories. Secrets Manager Agent picks up pre-fetching and cross-account role assumption, and Amazon Inspector Classic reaches end of support.
OpenAI GPT-5.5, GPT-5.4, and Codex reach general availability on Amazon Bedrock under the same governance controls as the rest of AWS. Amazon Cognito adds near-real-time multi-Region replication of identities and credentials, Bedrock AgentCore Identity integrates Secrets Manager, and two new CVEs hit Kiro IDE and Graph Explorer.
GuardDuty gets an on-demand investigation agent in public preview, Secrets Manager starts publishing secret-change events to EventBridge, and CloudTrail learns to filter network activity logging by identity. Five more bulletins close out July, including a TLS 1.3 record-drop flaw in s2n-tls and a third AgentCore SDK patch this summer.
Comprehensive guide to securing AWS Lambda functions. Covers execution role least privilege, Function URL authentication, VPC placement, code signing, environment variable encryption, Secrets Manager integration, and SnapStart security considerations.
Comprehensive guide to securing Amazon RDS databases. Covers encryption at rest and in transit, private subnet deployment, IAM database authentication, RDS Proxy, audit logging, Secrets Manager rotation, and snapshot security.
Comprehensive guide to securing AWS Secrets Manager. Covers automatic rotation, custom Lambda rotation, KMS encryption, resource policies, VPC endpoints, multi-region replication, batch retrieval, and continuous compliance.
Our AWS security experts can help you implement best practices across all these topics.
Contact Us