In June 2026, threat actors targeted Amazon EKS clusters by exploiting Kubernetes credentials or IAM roles to modify workloads and hijack compute resources. Attackers gained initial access through application-layer…
A recent cyber incident involved attackers compromising an AWS EC2 instance acting as an AI gateway for Amazon Bedrock, leading to the deployment of XMRig cryptomining malware. Researchers from Darktrace identified that…
Amazon Web Services (AWS) has linked a multi-year cyber espionage campaign targeting Western critical infrastructure, particularly in the energy sector, to the Russian GRU-affiliated group Sandworm (APT44). The campaign…
On March 31, 2026, HYCU, Inc. announced a major expansion of its R-Shield cyber resilience solution through a partnership with Halcyon, integrating advanced ransomware prevention and data exfiltration capabilities. This…
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
Trend Vision One has integrated with AWS Security Hub CSPM to improve AWS infrastructure security management. This integration allows organizations to streamline multiple security dashboards and tools, bringing critical…
A developer, referred to as 'Chase', accidentally triggered a significant increase in his AWS bill due to a single misclick while managing resources on AWS EC2. This incident highlights the potential financial risks…
Between February and September 2025, BlueDelta, a Russian state-sponsored group, conducted multiple credential-harvesting campaigns. These operations targeted users of UKR.NET, a popular Ukrainian webmail and news…
AWS has integrated its DevOps Agent with Wiz to improve incident investigations by adding security context. This integration allows the agent to distinguish between operational issues and security incidents by querying…
A sophisticated cryptocurrency mining campaign targeting AWS customers began on November 2, 2025, using compromised AWS Identity and Access Management (IAM) credentials. The attackers exploited Amazon Elastic Container…