Amazon GuardDuty is a technology platform tracked across 6 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 10, 2025; most recent activity June 29, 2026.
Amazon GuardDuty is AWS's managed threat-detection service for cloud environments. It continuously analyzes data from sources such as VPC Flow Logs, CloudTrail (Management and Data events), and DNS logs to identify malicious or unauthorized activity using machine learning and threat intelligence. Findings are surfaced in the AWS Console and can be integrated with SIEMs or automation tools to accelerate incident response.
Threat actors are exploiting AWS Organizations by using compromised credentials to remove accounts from organizations. This tactic allows them to bypass Service Control Policies (SCPs) and gain unrestricted access to…
In June 2026, threat actors targeted Amazon EKS clusters by exploiting Kubernetes credentials or IAM roles to modify workloads and hijack compute resources. Attackers gained initial access through application-layer…
Organizations are facing an evolving security landscape where advanced cyber threats leverage artificial intelligence to exploit vulnerabilities and automate attacks. Traditional security measures are inadequate as…
Trend Vision One has integrated with AWS Security Hub CSPM to improve AWS infrastructure security management. This integration allows organizations to streamline multiple security dashboards and tools, bringing critical…
On May 15, 2026, AWS introduced the AI Security Framework aimed at helping organizations secure AI workloads. The framework provides a structured model that aligns security controls with specific AI use cases, layers,…
Two cybersecurity job postings were published on April 1, 2026, highlighting openings for junior and entry-level positions in incident response and security operations. Recorded Future is seeking a Junior Incident…