AWS CloudTrail is a technology platform tracked across 6 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity June 11, 2026.
Threat actors are exploiting AWS Organizations by using compromised credentials to remove accounts from organizations. This tactic allows them to bypass Service Control Policies (SCPs) and gain unrestricted access to…
Threat actors are increasingly exploiting AWS CloudTrail and Google Cloud Logging to evade detection and manipulate logs. These attacks target organizations transitioning to cloud environments, where logging services…
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
On May 15, 2026, AWS introduced the AI Security Framework aimed at helping organizations secure AI workloads. The framework provides a structured model that aligns security controls with specific AI use cases, layers,…
The Open Cybersecurity Schema Framework (OCSF) aims to standardize security logs across various systems, enhancing interoperability and simplifying compliance reporting. Amazon Security Lake has introduced an ETL…
Ransomware actors are increasingly focusing on cloud-based assets, particularly Amazon Web Services (AWS) S3 buckets. Recent reports indicate that these groups are adapting their tactics to leverage cloud-native…