Skip to content
Threat Feed

September 2026 (30)

medium advisory

Detection of Unauthorized AWS Route 53 Private Hosted Zone Associations

Adversaries with high-level IAM permissions may associate unauthorized VPCs with AWS Route 53 private hosted zones to intercept internal DNS traffic, establish persistence, or perform reconnaissance.

AWS Route 53 +1 aws cloud persistence route53
1r 3t updated
high advisory

Detection of AWS Route 53 Resolver Query Log Deletion

Adversaries may delete Amazon Route 53 Resolver Query Log configurations to evade detection by disabling DNS query and response logging for VPC-based resources.

Route 53 cloud aws defense-evasion log-auditing persistence resource-development
2r 3t
medium advisory

Detection of Unauthorized Public Exposure of AWS RDS Instances

Adversaries with compromised AWS credentials may set the publiclyAccessible attribute to true during RDS instance creation or modification to facilitate data exfiltration, establish persistence, or bypass internal network boundaries.

RDS aws cloud persistence defense-evasion
1r 2t
medium advisory

Abuse of AWS IAM Roles Anywhere via External Trust Anchors

Adversaries can establish persistent access to AWS environments by creating an IAM Roles Anywhere Trust Anchor using an unauthorized external Certificate Authority (CA) to sign forged client certificates.

AWS IAM Roles Anywhere cloud aws persistence iam
1r 2t
high advisory

AWS IAM OpenID Connect Provider Creation by Rare User

Adversaries with administrative access to an AWS account may create rogue OpenID Connect (OIDC) Identity Providers to establish persistent, federated access that bypasses credential rotation and allows them to assume IAM roles using tokens from an attacker-controlled Identity Provider.

IAM +1 cloud-security persistence privilege-escalation defense-evasion aws
1r 3t updated
high advisory

AWS Root Account Persistence via CreateLoginProfile

Adversaries with temporary root access may invoke the CreateLoginProfile API without a username to establish persistent console password access for the AWS root principal.

AWS persistence cloud identity-and-access-audit
1r 2t
high advisory

Suspicious AWS IAM API Calls via Temporary Session Tokens

This detection rule identifies suspicious AWS IAM API operations performed using temporary session credentials (access keys starting with ASIA) that are not sourced from console logins, indicating potential credential theft, session hijacking, or abuse of privileged temporary credentials by an attacker for persistence, privilege escalation, or defense evasion within the AWS environment.

AWS IAM +4 cloud aws persistence privilege-escalation defense-evasion
1r 2t updated
low advisory

Detection of Unauthorized Amazon Bedrock Foundation Model Access Attempts

Detection of failed API calls attempting to enable Amazon Bedrock foundation model access, serving as a high-signal indicator for credential boundary-testing and potential LLMjacking.

Bedrock cloud aws llmjacking persistence
1r 1t
high advisory

AWS IAM Virtual MFA Device Registration Attempt with Session Token

Adversaries are exploiting compromised temporary AWS session credentials (access keys starting with 'ASIA') to register or enable virtual MFA devices, establishing persistence and maintaining access to high-privilege accounts even after credential rotation or password resets.

IAM +3 cloud aws persistence identity-and-access-audit
1r 3t updated
high advisory

AWS Lateral Movement via Kubernetes Service Account Identity Exploitation

Adversaries are exploiting Kubernetes service account tokens exchanged for AWS IAM credentials via AssumeRoleWithWebIdentity to conduct unauthorized reconnaissance, credential theft, and persistent access within AWS environments.

AWS Elastic Kubernetes Service +3 cloud aws lateral-movement credential-access discovery
4t
high advisory

Abuse of AWS S3 SSE-C for Ransomware Extortion

Adversaries with compromised AWS credentials can abuse Server-Side Encryption with Customer-Provided Keys (SSE-C) to encrypt S3 objects with attacker-controlled keys, effectively holding organizational data for ransom.

S3 cloud aws ransomware
1r 1t
medium advisory

AWS RDS Deletion Protection Disabled

Adversaries with elevated IAM permissions may disable deletion protection on AWS RDS instances or clusters as a prerequisite for unauthorized data destruction.

RDS +1 cloud aws impact defense-evasion
1r 2t updated
medium advisory

Abuse of AWS KMS DeleteImportedKeyMaterial for Data Sabotage

Adversaries can perform immediate data destruction in AWS by invoking the DeleteImportedKeyMaterial API, rendering all data protected by external-origin (BYOK) keys inaccessible without a recovery window.

AWS KMS cloud aws kms impact sabotage
1r 1t
high advisory

Detection of Unauthorized AWS Backup Recovery Point Deletion

Unauthorized deletion of AWS Backup recovery points via the DeleteRecoveryPoint API is an anti-recovery technique used by adversaries to prevent data restoration following destructive or ransomware attacks.

AWS Backup impact cloud-security aws ransomware
1r 1t
medium advisory

AWS RDS Database Snapshot Unauthorized External Sharing

Adversaries may exfiltrate sensitive data from AWS RDS by modifying snapshot attributes to share them with an external, attacker-controlled AWS account, enabling unauthorized offline access to the database content.

Amazon RDS cloud exfiltration aws rds
1r 1t
medium advisory

AWS ECR Repository or Registry Policy Granted Public Access

Detection of unauthorized configuration changes to AWS ECR policies that grant public access via wildcard principals, potentially leading to container image exfiltration or supply chain implantation.

Elastic Container Registry cloud aws exfiltration ecr
1r 1t
medium advisory

AWS EC2 EBS Snapshot Exfiltration via ModifySnapshotAttribute

Adversaries may exploit the ModifySnapshotAttribute API to share Amazon EBS snapshots with external accounts or the public, facilitating data exfiltration and unauthorized access to sensitive volume data.

Amazon Web Services +1 cloud exfiltration aws monitoring
1t
high advisory

AWS EC2 AMI Shared with Another Account

Adversaries with existing AWS access may exfiltrate sensitive data by sharing Amazon Machine Images (AMIs) containing secrets, bash histories, or code artifacts with external, attacker-controlled AWS accounts, detectable via `ModifyImageAttribute` actions in AWS CloudTrail logs.

Amazon EC2 +3 cloud aws exfiltration ami
1r 1t 4i updated
low advisory

Detection of Anomalous AWS DynamoDB Scan Operations

This detection brief identifies potential data exfiltration or unauthorized collection by monitoring for unusual AWS DynamoDB Scan operations performed by users or roles exhibiting non-typical behavior.

DynamoDB cloud aws exfiltration detection
3t
high advisory

Abuse of AWS Systems Manager for Remote LOLBin Execution

Adversaries are abusing the AWS Systems Manager SendCommand API to remotely execute commands on EC2 instances by leveraging legitimate system utilities (LOLBins) to bypass CloudTrail parameter redaction.

EC2 +2 cloud linux aws living-off-the-land execution command-and-control defense-evasion cloud-administration-command
1r 4t
medium advisory

Detection of Anomalous Direct AWS Lambda Function Invocations

This threat brief details the risk of unauthorized or lateral movement via direct AWS Lambda function invocation by non-standard principals, highlighting detection methodologies for cloud environments.

AWS Lambda cloud aws lambda execution
1t
low advisory

AWS S3 Rapid Bucket Posture API Calls from a Single Principal

This detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.

S3 +2 aws cloudtrail discovery collection reconnaissance cloud
4t updated
high advisory

LLMjacking via Compromised AWS Long-Term IAM Credentials

Adversaries are abusing stolen long-term AWS IAM access keys to perform unauthorized reconnaissance and high-cost model inference within Amazon Bedrock.

Amazon Bedrock cloud llm aws llmjacking identity-audit
1r 2t
medium advisory

Detection of Unauthorized AWS WAF Rule Deletion

Adversaries may delete AWS WAF rules or rule groups via API to impair security boundaries and facilitate follow-on exploitation of web applications.

AWS WAF cloud aws defense-evasion
1r 1t
medium advisory

AWS SQS PurgeQueue Defense Evasion

Adversaries may use the PurgeQueue action in AWS Simple Queue Service (SQS) to permanently delete all messages within a queue to disrupt operations, destroy forensic evidence, or evade detection.

Simple Queue Service cloud defense-evasion impact aws
1r 2t
medium advisory

Detection of Unauthorized AWS RDS Instance Restoration

Threat actors with compromised AWS credentials may use RDS restoration operations to duplicate sensitive database environments, facilitating unauthorized data access, staging, and exfiltration while bypassing production monitoring controls.

Relational Database Service cloud defense-evasion collection aws
1r 3t
high advisory

AWS GuardDuty Member Account Manipulation

Adversaries manipulate Amazon GuardDuty member accounts within an AWS organization by using API calls such as `DisassociateFromAdministratorAccount`, `DeleteMembers`, `StopMonitoringMembers`, or `DeleteInvitations` to break centralized security visibility, enabling them to operate undetected in compromised member accounts.

Amazon GuardDuty +1 cloud aws defense-evasion amazon-guardduty
1r 1t updated
medium advisory

Detection of Anomalous AWS IAM Long-Term Access Key Usage

This brief describes a detection capability for identifying potentially unauthorized programmatic access by monitoring for successful AWS IAM long-term access key usage originating from previously unseen source IP addresses.

AWS IAM +1 cloud aws credential-access initial-access
2t
medium advisory

AWS S3 Bucket ACL Modification to Public Access by New Identity

Detection of unauthorized S3 bucket ACL modifications to public-read or public-read-write by previously unseen identities, potentially indicating credential compromise for data exfiltration.

AWS S3 +1 cloud aws collection s3
1r 1t updated
low advisory

Detection of Web Server Reconnaissance via Error Log Spikes

This brief covers the detection of automated reconnaissance activities, such as vulnerability scanning and fuzzing, which manifest as significant spikes in web server error logs.

HTTP Server +2 reconnaissance web-security log-analysis
1r 3t