EC2 — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 5, 2025
Last Seen
July 26, 2026

Related Threat Clusters

  • Cryptomining Attack Exploits AI Gateway Vulnerabilities in AWS

    A recent cyber incident involved attackers compromising an AWS EC2 instance acting as an AI gateway for Amazon Bedrock, leading to the deployment of XMRig cryptomining malware. Researchers from Darktrace identified that…

    4 articles · Updated July 9, 2026
  • Denial of Service Vulnerability in Fedora Moby Engine

    A Denial of Service vulnerability (CVE-2026-47262) was identified in the Fedora Moby Engine, specifically affecting the containerd component. This vulnerability allows attackers to exploit maliciously crafted images,…

    2 articles · Updated July 26, 2026
  • AWS Security Hub Expands AI Workload Protection and Azure Monitoring

    AWS has enhanced its Security Hub by adding AI workload protection and monitoring for Microsoft Azure, addressing customer demands for multicloud security. The updates aim to improve threat detection and response times…

    6 articles · Updated July 14, 2026
  • Wiz Launches AI-Powered Red Agent for Vulnerability Detection

    Wiz has introduced the Red Agent, an AI-powered tool designed to identify complex vulnerabilities in proprietary APIs and AI-generated code. The Red Agent leverages advanced AI exploitation techniques to discover…

    2 articles · Updated March 23, 2026
  • Enterprise AI Faces Security Challenges Amid Rising Investments

    Despite a significant increase in AI investments, with 86% of C-suite executives boosting budgets, only 32% report a sustained impact from these initiatives. New security threats such as prompt injection and shadow AI…

    9 articles · Updated July 7, 2026
  • AWS EC2 Outage Disrupts Services Due to Power Loss in US-EAST-1 Region

    Amazon Web Services (AWS) reported a power outage affecting its EC2 instances in the US-EAST-1 region on May 7, 2026. The outage was caused by overheating in a single availability zone, leading to impairments in EC2…

    2 articles · Updated May 8, 2026
  • Google GTIG Reports Shift in AI Misuse by Cyber Adversaries

    The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…

    3 articles · Updated November 5, 2025
  • Shift in Ransomware Tactics Targeting Cloud Assets

    Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…

    56 articles · Updated November 19, 2025
  • AWS IAM Credential Theft Fuels Ongoing Crypto Mining Campaign

    A sophisticated cryptocurrency mining campaign targeting AWS customers began on November 2, 2025, using compromised AWS Identity and Access Management (IAM) credentials. The attackers exploited Amazon Elastic Container…

    5 articles · Updated December 17, 2025
  • Ransomware Gangs Target AWS S3 Buckets with Evolving Tactics

    Ransomware actors are increasingly focusing on cloud-based assets, particularly Amazon Web Services (AWS) S3 buckets. Recent reports indicate that these groups are adapting their tactics to leverage cloud-native…

    4 articles · Updated November 21, 2025

Recent Intelligence Reports

  • Fedora 44 moby-engine Denial of Service Security Advisory 2026 — Linuxsecurity · July 26, 2026
  • AWS will now watch Microsoft's cloud for you — Thenewstack · July 15, 2026
  • Attack on Amazon Bedrock — Csoonline · July 9, 2026
  • The real cost, security, and culture problems behind enterprise AI agents — Venturebeat · July 7, 2026
  • AWS warns of EC2 ‘impairment’ as power loss hits notorious US-EAST — Theregister · May 8, 2026
  • Introducing the Wiz Red Agent- AI-Powered Attacker — Wiz · March 23, 2026
  • AI agents solve 9 of 10 web security CTF challenges in recent study — Scmagazine · January 30, 2026
  • Amazon: Ongoing cryptomining campaign uses hacked AWS accounts — Bleepingcomputer · December 17, 2025

CVSS v3.1 Breakdown