News.Risky.Biz
AWS Introduces Bucketsquatting Protection Amid Rising Threats
Article Content
Amazon Web Services (AWS) has implemented a new security feature to combat S3 Bucket Namesquatting, also known as Bucketsquatting, which allows attackers to exploit predictable naming conventions in AWS bucket names. This attack method involves registering bucket names that have been abandoned or deleted, potentially allowing attackers to intercept data routed to these buckets. The new feature ties bucket names to account IDs and regional namespaces, enhancing security for new buckets. However, existing buckets remain vulnerable unless users create new ones and migrate their data. The issue gained attention when researchers registered 150 previously owned buckets, some still receiving traffic from sensitive domains. AWS's new protection does not retroactively secure existing buckets, highlighting the need for users to take action. Other cloud providers like Azure and Google Cloud have implemented different protective measures against similar threats.
Key Points: • AWS has launched a feature to prevent S3 Bucket Namesquatting attacks. • Existing buckets remain vulnerable unless users migrate to new ones with the updated security. • The issue gained attention after researchers registered 150 abandoned AWS buckets still receiving traffic.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.