Skip to content
Threat Feed

Briefs

← Newer Older →

September 2026 (30)

medium advisory

Detection of AWS EC2 Deprecated AMI Discovery

Detection of reconnaissance activity where AWS users or roles query the EC2 API for deprecated Amazon Machine Images, a technique used by adversaries to identify vulnerable or outdated system images for potential exploitation.

Amazon EC2 cloud-security discovery aws cloud exfiltration collection persistence defense-evasion
3r 7t updated
medium advisory

Detection of Unauthorized AWS Bedrock Model Import and Deployment

Unauthorized importation or deployment of AI models in AWS Bedrock can facilitate a supply-chain compromise by introducing backdoored or poisoned artifacts into an organization's inference pipeline.

AWS Bedrock cloud bedrock llm persistence
1r 1t
high advisory

Detection of Unauthorized AWS EC2 GetPasswordData API Access

Adversaries may attempt to retrieve EC2 administrator passwords via the GetPasswordData API to facilitate privilege escalation or lateral movement within AWS environments.

AWS EC2 +3 aws cloud credential-access identity-and-access-audit incident-response ransomware persistence defense-evasion +4
5r 10t updated
medium advisory

Detection of Adversary-in-the-Middle Session Theft via Geographic Implausibility

This brief describes a method for detecting Adversary-in-the-Middle (AiTM) phishing and session theft in AWS environments by identifying IAM user console logins originating from geographically distinct locations within a short timeframe.

AWS Management Console +1 cloud-security aws session-theft identity
2t updated
medium advisory

Detecting S3 Ransomware via Cross-Account KMS Encryption

Adversaries leverage S3 CopyObject API calls to encrypt data within victim buckets using external, attacker-controlled KMS keys, effectively denying access to the bucket owner.

S3 +3 cloud aws ransomware impact
1t updated
high advisory

AWS S3 Bucket MFA Delete Disablement

Adversaries may disable MFA Delete on versioned Amazon S3 buckets to enable the permanent destruction of object version history, a critical step in ransomware attacks targeting cloud-native backups.

AWS S3 +1
1r 1t updated
medium advisory

AWS KMS Customer Managed Key Lifecycle Manipulation

Adversaries may disable or schedule the deletion of AWS KMS keys to sabotage business operations, render encrypted data unrecoverable, and obstruct forensic investigation or incident response efforts.

AWS Key Management Service +1 impact cloud-security aws-kms incident-response
1r 1t updated
medium advisory

Detection of Unauthorized S3 Bucket Public Access Policies

Adversaries may modify Amazon S3 bucket policies to include a wildcard ('*') principal with 'Allow' permissions, effectively making bucket contents publicly accessible for data exfiltration.

S3 +1 cloud aws exfiltration collection
1r 2t updated
medium advisory

Abuse of AWS EC2 Export APIs for Data Exfiltration

Adversaries with compromised AWS credentials can exploit EC2 export APIs to copy entire virtual machine states or images to external storage for data exfiltration.

Elastic Compute Cloud +1 cloud exfiltration collection aws
1r 2t updated
low advisory

Detection of Unauthorized AWS Lambda Layer Modifications

Adversaries with compromised credentials may modify AWS Lambda configurations by injecting unauthorized layers to establish persistence, run arbitrary code, or intercept data.

AWS Lambda +1 cloud aws lambda persistence execution
1r 2t updated
medium advisory

Abuse of AWS Systems Manager Session Manager for Remote Execution

Adversaries abuse AWS Systems Manager (SSM) Session Manager to gain interactive shell access and perform remote command execution on EC2 instances or managed hybrid nodes.

AWS Systems Manager +1 cloud-security remote-execution lateral-movement cloud aws discovery reconnaissance
2r 5t updated
medium advisory

Detection of AWS SES Identity Verify-Use-Delete Abusive Pattern

Adversaries with unauthorized access to AWS Simple Email Service (SES) credentials may verify an attacker-controlled identity, send phishing or spam emails, and promptly delete the identity to evade detection and attribution.

Simple Email Service +2 cloud aws ses resource-development defense-evasion discovery credential-abuse
1r 3t updated
low advisory

Monitoring AWS CloudTrail Creation for Unauthorized Log Diversion

Adversaries may use the CreateTrail API to establish unauthorized logging configurations that redirect audit data to attacker-controlled destinations or circumvent existing monitoring controls.

AWS CloudTrail +1 cloud aws log-auditing discovery cloudtrail
1r 4t updated
medium advisory

Monitoring Unauthorized AWS Security Group Modifications

Adversaries modify AWS VPC security group ingress rules to permit unrestricted external access to sensitive management ports, facilitating remote access or future exploitation of cloud instances.

EC2 +2
1r 2t updated
medium advisory

AWS GuardDuty Publishing Destination Deletion

Adversaries with administrative access to AWS GuardDuty may delete publishing destinations to break security finding exports, effectively blinding SOC monitoring without triggering detector-disabling alerts.

GuardDuty cloud aws defense-evasion
1r 1t
medium advisory

AWS CloudTrail Defense Evasion via DeleteTrail API

The deletion of AWS CloudTrail trails via the DeleteTrail API is a high-risk indicator of defense evasion or sabotage used to eliminate audit visibility.

CloudTrail cloud defense-evasion aws
1r 1t
medium advisory

Unauthorized Access to Sensitive Files in AWS S3

This detection brief addresses the risk of unauthorized access to sensitive credential and secret files stored in AWS S3 buckets, a common tactic for credential harvesting and lateral movement.

AWS S3 +1 cloud-security credential-access aws exfiltration s3 cloud discovery impact +1
3r 6t updated
medium advisory

Unauthenticated AWS S3 Bucket Access via Misconfigured Policies

Adversaries leverage misconfigured S3 bucket policies to perform unauthenticated data collection, discovery, and manipulation using tools like the AWS CLI without authentication.

Amazon S3 +1 cloud aws s3 collection discovery impact
4t updated
high advisory

Detection of Privilege Escalation via Unauthorized Sudoers Modification

Adversaries may attempt to gain elevated privileges on Unix-like systems by using the echo command to inject NOPASSWD directives into the sudoers file, allowing passwordless execution of commands as root.

privilege-escalation defense-evasion linux macos
1r 2t updated
low advisory

Web Server Potential Command Injection via HTTP Requests

Threat actors are exploiting web application command injection vulnerabilities to execute arbitrary code by submitting crafted HTTP requests containing interpreter invocations, downloader utilities, or shell commands.

Nginx +4 command-injection web-shell web-application reconnaissance persistence execution
2t updated
high advisory

Detection of Assets with Elevated Vulnerability Exposure via Wiz

This brief describes a detection capability designed to identify cloud assets exhibiting poor security posture by correlating high volumes of vulnerabilities, exploitable findings, and critical-severity bugs reported by the Wiz Cloud Security Platform.

Wiz Cloud Security Platform vulnerability-management cloud-security wiz
1t
critical advisory

Automated LLM-Based User Account Compromise Triage

An automated detection framework that uses Large Language Models to correlate disparate security alerts and assess potential account compromise based on behavioral indicators.

Elastic Stack +1 identity-compromise llm-security detection-engineering automated-triage
3t updated
medium advisory

Unauthenticated External Exposure of Ollama LLM API

Improper configuration of the Ollama LLM server can expose the API to the internet without authentication, enabling remote attackers to conduct model theft, prompt injection, and resource hijacking.

Ollama initial-access llm-security
1r 2t updated
medium advisory

Detection of Unauthorized Hosts File Modifications

Adversaries manipulate endpoint hosts files to intercept network traffic, enabling malicious infrastructure redirection or the disruption of security services such as MFA.

impact persistence cross-platform
1r 1t updated
medium advisory

Unauthorized Command Execution via Self-Hosted GitHub Actions Runners

Adversaries gaining unauthorized workflow trigger access can abuse GitHub Actions runners to execute arbitrary system commands, potentially leading to credential harvesting, reconnaissance, and CI/CD supply chain compromise.

GitHub Actions +1 execution supply-chain ci-cd lotl
1r 1t updated
medium advisory

Detection of Unauthorized Kubernetes API Interaction via CLI Tools

Adversaries leverage standard command-line tools like curl or wget to perform unauthorized discovery and credential access by querying sensitive Kubernetes API endpoints directly, bypassing legitimate management tooling.

Kubernetes API +1
1r 3t updated
medium advisory

Detection of Unauthorized Interactive Kubernetes API Probing

Adversaries performing hands-on-keyboard enumeration within compromised containers are detected by correlating interactive process execution with forbidden Kubernetes API audit responses.

Kubernetes +1 execution discovery cloud-native container-security container threat-detection
3t updated
low advisory

Web Server Local File Inclusion Activity

This brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.

Nginx +4 local-file-inclusion web-vulnerability information-disclosure remote-code-execution discovery
1r 4t 1i updated
medium advisory

Potential Kubernetes Impersonation via Kubectl Flags

Adversaries may perform unauthorized impersonation within Kubernetes clusters by executing the 'kubectl' command-line tool with sensitive flags like '--as' or '--token' to escalate privileges or bypass access controls.

kubectl defense-evasion kubernetes container-security
1r 2t updated
medium advisory

Detection of Web Server Access Log Deletion

Adversaries often delete web server access logs to destroy forensic evidence and evade detection after unauthorized activity, a behavior monitorable through file deletion events on common web server log paths.

HTTP Server +1 defense-evasion file-integrity logs cross-platform
1r 1t updated