AWS Account Compromised During Outage: 600 Instances Spawned in 3 Hours
By
kinj28
Hard crust, hollow middle. Skim only.
Summary
A user reports their AWS account was compromised with 600 instances spawned within 3 hours during an AWS outage, raising questions about potential connection between the two events. The compromise involved domain verification attempts and SES quota increase requests. The user is investigating potential vulnerabilities including API keys or console access without MFA.
Key quotes
· 4 pulledSome 600 instances were spawned within 3 hours before AWS flagged it off and sent us a health event.
There were numerous domains verified and we could see SES quota increase request was made.
Our initial suspect list has 2 suspects: api key or console access where MFA wasn't enabled.
Could there be any link between the two events?
You might also wanna read
Security Vulnerability in Snowflake Cortex Code CLI Allows Malware Execution via Prompt Injection
A security vulnerability was discovered in Snowflake's Cortex Code CLI tool just two days after its release. The vulnerability allowed attac
promptarmor.com·2mo agoCritical AWS Supply Chain Vulnerability: CodeBreach Allowed Takeover of Key GitHub Repositories
Wiz Research discovered CodeBreach, a critical supply chain vulnerability in AWS that allowed attackers to potentially take over key AWS Git
Prompt Injection Attacks: The Top Security Threat Hijacking AI Chatbots
Prompt injection attacks are a critical security vulnerability in AI systems where hidden instructions within user data (like emails or docu
Quantum computing's security threats demand urgent preparation from IT professionals
The article discusses the impending quantum computing revolution and its dual nature: promising transformative advances while simultaneously
zdnet.com·18h agoCISA warns security teams of wave of attacks targeting software supply chain credentials
CISA has issued a warning urging security teams to check for software development compromises, specifically regarding a wave of attacks targ
Security Researchers Expose Weak Encryption in Canon Enterprise Printers
During a network security assessment, security researchers discovered that Canon enterprise printers configured with default administrator c
securityboulevard.com·1d ago