News.Risky.Biz
AWS Introduces Bucketsquatting Protection Amid Rising Threats
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Amazon Web Services (AWS) has implemented a new security feature to combat S3 Bucket Namesquatting, also known as Bucketsquatting, which allows attackers to exploit predictable naming conventions in AWS bucket names. This attack method involves registering bucket names that have been abandoned or deleted, potentially allowing attackers to intercept data routed to these buckets. The new feature ties bucket names to account IDs and regional namespaces, enhancing security for new buckets. However, existing buckets remain vulnerable unless users create new ones and migrate their data. The issue gained attention when researchers registered 150 previously owned buckets, some still receiving traffic from sensitive domains. AWS's new protection does not retroactively secure existing buckets, highlighting the need for users to take action. Other cloud providers like Azure and Google Cloud have implemented different protective measures against similar threats.
Key Points: • AWS has launched a feature to prevent S3 Bucket Namesquatting attacks. • Existing buckets remain vulnerable unless users migrate to new ones with the updated security. • The issue gained attention after researchers registered 150 abandoned AWS buckets still receiving traffic.