Tag AWS

Twitch Experiences Major 125GB Data and Source Code Breach Due to Server Misconfiguration

Title: Twitch Faces Security Breach as Comprehensive Data Leak Exposes Internal Systems In a significant security incident, popular livestreaming platform Twitch has confirmed a data breach that exposed its source code, internal tools, and creator payout details. The breach came to light after an anonymous contributor leaked a trove of…

Read MoreTwitch Experiences Major 125GB Data and Source Code Breach Due to Server Misconfiguration

Vulnerability in Amazon WorkSpaces for Linux Enables Extraction of Valid Authentication Tokens

A severe security vulnerability has been identified in the Amazon WorkSpaces client for Linux, posing a substantial risk for organizations utilizing AWS’s virtual desktop infrastructure. This flaw, designated as CVE-2025-12779, allows malicious local users to extract valid authentication tokens, leading to unauthorized access to other users’ Workspace sessions. On November…

Read MoreVulnerability in Amazon WorkSpaces for Linux Enables Extraction of Valid Authentication Tokens

How Hidden Secrets in Source Code Can Cause Major Breaches

The Rise of Supply Chain Attacks: A Growing Concern for Businesses In 2021, the cybersecurity landscape was notably defined by a surge in supply chain attacks. These incidents occur when cybercriminals compromise third-party software components to infiltrate downstream applications. High-profile breaches such as those involving SolarWinds, Kaseya, and Codecov have…

Read MoreHow Hidden Secrets in Source Code Can Cause Major Breaches

Uber Asserts No Sensitive Data Compromised in Recent Breach, Yet There’s More to the Story

Uber Technologies Inc. has recently acknowledged a security breach affecting its internal computer systems, first reported late Thursday. The company stated that there is currently “no evidence” suggesting that sensitive user data, such as trip history, has been accessed during the incident. In a public statement, Uber clarified, “We have…

Read MoreUber Asserts No Sensitive Data Compromised in Recent Breach, Yet There’s More to the Story

AWS Cloud Development Kit Vulnerability Poses Risk of Potential Account Takeover for Users

Security Vulnerability Discovered in AWS Cloud Development Kit Cybersecurity researchers have unveiled a significant vulnerability within the Amazon Web Services (AWS) Cloud Development Kit (CDK), which may allow for account takeovers under certain conditions. The findings, disclosed by Aqua researchers Ofek Itach and Yakir Kadkoda, indicate that an attacker could…

Read MoreAWS Cloud Development Kit Vulnerability Poses Risk of Potential Account Takeover for Users

Malicious PyPI Package ‘Fabrice’ Discovered Exfiltrating AWS Keys from Thousands of Developers

Malicious Python Package on PyPI Steals AWS Credentials Cybersecurity researchers have identified a malicious package on the Python Package Index (PyPI) that has been quietly exfiltrating Amazon Web Services (AWS) credentials from unsuspecting developers for over three years. The package, named “fabrice,” exploits a common typo of the highly regarded…

Read MoreMalicious PyPI Package ‘Fabrice’ Discovered Exfiltrating AWS Keys from Thousands of Developers

Amazon Details How Its AWS Outage Disrupted the Internet

Amazon Web Services (AWS) faced significant downtime on Monday due to Domain Name System (DNS) resolution issues that triggered widespread disruptions across various online platforms. This incident underscored the global dependency on large cloud service providers, known as hyperscalers, and highlighted the complications both for these companies and their clients…

Read MoreAmazon Details How Its AWS Outage Disrupted the Internet