Collected every two hours from specialised publications — each link leads to the original article.
An openSUSE Tumbleweed update for amazon-ecs-init addresses a vulnerability, CVE-2026-56852, rated moderate, with various CVSS scores indicating severity and i…
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums r…
openSUSE released a security update for aws-nitro-enclaves-cli, addressing seven vulnerabilities, including buffer overflows and arbitrary code execution, alon…
CVE-2026-12957 in Amazon Q is the third MCP auto-execution vulnerability in three AI coding tools. The pattern reveals a shared design failure, not just a sing…
A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer o…
Cybersecurity researchers have disclosed a new type of name confusion attack called whoAMI that allows anyone who publishes an Amazon Machine Image (AMI) with …
Cybersecurity researchers have disclosed a security flaw impacting Amazon Web Services (AWS) Cloud Development Kit (CDK) that could have resulted in an account…
As many as 15,000 applications using Amazon Web Services' (AWS) Application Load Balancer (ALB) for authentication are potentially susceptible to a configurati…
As many as 15,000 applications using Amazon Web Services' (AWS) Application Load Balancer (ALB) for authentication are potentially susceptible to a configurati…
AWS has patched a vulnerability in its Elastic Container Registry (ECR) that was uncovered by Lightspin researcher Gafnit Amiga during an examination of AWS's …
A critical security flaw has been disclosed in Amazon Elastic Container Registry (ECR) Public Gallery that could have been potentially exploited to stage a mul…
Amazon Web Services (AWS) has resolved a cross-tenant vulnerability in its platform that could be weaponized by an attacker to gain unauthorized access to reso…
A severe security bug existed in the AWS IAM Authenticator for Kubernetes. Exploiting this vulnerability…Authentication Bypass Bug Found In AWS IAM Authenticat…
Researchers discovered a severe security vulnerability in the Android Photos app that exposed Amazon access…High-Severity Vulnerability Found In Amazon Photos …
The container caasp/v4/velero-plugin-for-aws was updated. The following patches have been included in this update:
Amazon Web Services has announced that it will release an updated version of its own Linux every two years, starting with Amazon Linux 2022, which it is previe…
The container caasp/v4.5/velero-plugin-for-aws was updated. The following patches have been included in this update:
Attention! If you use Amazon's voice assistant Alexa in you smart speakers, just opening an innocent-looking web-link could let attackers install hacking skill…
Researchers have found numerous security vulnerabilities affecting the home assistant Amazon Alexa. Exploiting the vulnerabilities could leak sensitive details…
Researchers have found numerous security vulnerabilities affecting the home assistant Amazon Alexa. Exploiting the vulnerabilities could leak sensitive details…
Attention! If you use Amazon's voice assistant Alexa in you smart speakers, just opening an innocent-looking web-link could let attackers install hacking skill…
Security researchers at Bitdefender have discovered a high-severity security vulnerability in Amazon's Ring Video Doorbell Pro devices that could allow nearby …
Continuing on the trail of smart security systems exhibiting security issues, now joins Amazon's smart doorbells. Researchers found a seriousVulnerability Foun…
Researchers have recently discovered a security vulnerability targeting Amazon Kindle and Echo devices. The KRACK WiFi vulnerability discovered back inAmazon K…