Issue #265
Monday · June 15, 2026
๐ฅ Palate Cleanser
This week's drama llama gave us AWS Bedrock quietly breaking its own core promise. On June 9 Anthropic launched its new flagship Claude models, Fable 5 and Mythos 5, and AWS lit them up on Bedrock the same day. The catch, buried in the docs, is that the only way to use them is to let your prompts and outputs leave the AWS boundary and go to Anthropic, where they are kept for up to 30 days and can be read by humans. Bedrock's longstanding promise that model providers never see your prompts and completions, and that invocations stay inside the AWS network, is gone for these two models.
Chris Farris fired the first shot on June 10 with "AWS Destroyed the Value Proposition for Bedrock" (in Chef's Selections), and the reaction was loud. A 400+ point Hacker News thread, EU data-residency alarm, and Microsoft reportedly pulling Fable 5 from internal Copilot use over the same retention policy. Worth keeping the headline honest, though. The change is scoped to the new Mythos-class models, not Opus 4.8, Sonnet, or Haiku, which keep their existing zero-retention behavior, and accounts pinned to zero data retention simply have these model calls blocked rather than silently sharing data. AWS also says the data leaves its boundary while Anthropic says it stays in AWS, which might be reconcilable but not a great look. Then on June 12 the whole debate got overtaken: Anthropic disabled both models globally to comply with a US export-control directive restricting foreign-national access. So for now this is a fight about Bedrock's direction rather than a live buying decision.
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
๐ Chef's selections
-
AWS Destroyed the Value Proposition for Bedrock by Chris Farris
For the new flagship Claude models (Fable 5, Mythos 5) on AWS Bedrock, the only "allowed_mode" is "provider_data_share". That means prompts and outputs are shared with and retained by Anthropic for 30 days with human review access. This turns Bedrock from a neutral broker that shielded customer data into "first-party Anthropic," with real data-residency and CLOUD Act exposure, and no advance warning for compliance teams.
-
Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility by Yahav Festinger
StopLogging is the most direct way to kill CloudTrail, so Yahav catalogues the quieter techniques like repointing a trail at an attacker-controlled KMS key with UpdateTrail then revoking CloudTrail's access so logs silently stop landing in S3, and redirecting log delivery to an attacker's own account for persistent visibility. The AWS content is mostly well-trodden ground I mapped years ago in Disrupting AWS logging, which goes deeper (KMS-immutable deletion, bucket-policy denial, S3 lifecycle auto-expiry, and Lambda-driven log deletion).
-
Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets by Itay Yashar
Enterprises are wiring AI agents straight into the inbox to triage and reply to mail, so Itay built one ("Pinchy") on a real Google Workspace mailbox to test whether decades-old phishing tricks still land on a machine. They do. Even with a hardened "Strict" security profile that explicitly told it to verify identities first, an urgent "Dan needs staging access" email citing a production emergency got the agent to forward AWS IAM keys, database connection strings, and SSH credentials to an external Gmail. The piece draws a sharp line between this and indirect prompt injection, and shows agents are good at spotting technical tells like malicious OAuth redirect URIs but fall for the same social pretexts that fool humans.
๐ธ Sponsor shoutout
Meet Pleri: your AI security engineer. Sheโs not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.
Learn more about Pleri and see her in action.
๐ฅ AWS security blogs
- ๐ฃ Amazon Quick now integrates with Snowflake Cortex AI
- ๐ฃ AWS announces AWS Workload Credentials Provider
- ๐ฃ OpenAI GPT-5.4 and GPT-5.5 models now available in US East (N. Virginia) on Amazon Bedrock
- ๐ฃ Gemma 4 models now available on Amazon Bedrock
- ๐ฃ AWS Lambda Managed Instances expands to additional AWS Regions
- Transfer AWS accounts between AWS Organizations while preserving AWS Lake Formation permissions by Alex Torres
- Unified Secrets Security with GitGuardian and AWS Secrets Manager by Nic Gumina
- Automate compliance session review with Teleport and Amazon Bedrock by JP Boreddy
- Avoid shared database accounts with federated IAM authentication by Kishore Dhamodaran
- Built from the inside out: How AWS Professional Services became a frontier team first by Francessca Vasquez
- Extending SD-WAN Segmentation into AWS Cloud WAN โ Part 2 by Mevlit Mustafa
- Extending SD-WAN Segmentation into AWS Cloud WAN โ Part 1 by Mevlit Mustafa
- Securing zero trust access with AWS Verified Access and AWS Network Firewall by Ruskin Dantra
- How the Maritime Cloud Environment accelerates Navy shipbuilding by Chris Canniff
- Preventive controls for FedRAMP 20x: Using SCPs and guardrails to enforce KSIs by Dr. Tommy Kromer
- Evaluating ITAR workloads in US commercial AWS Regions by Samuel J. Zhang
- ICYMI: May 2026 @AWS Security by Rodolfo Brenes
- Operationalizing AWS security: A maturity roadmap by Joseph Sadler
- Secure shared storage with CIFS share-level access controls on Amazon FSx for NetApp ONTAP by Aravindan A
๐ Reddit threads on r/aws
๐ค Dessert
Every machine-tracked change this week. Nobody else assembles this.
๐ง IAM permission changes
๐ช API changes
- Amazon Bedrock AgentCore Control
- Amazon Bedrock AgentCore
- AWS DevOps Agent Service
- Amazon Elastic Kubernetes Service
- AWS Glue
- Amazon SageMaker Runtime
- Amazon Bedrock AgentCore Control
- Amazon Elastic Kubernetes Service
- Amazon HealthLake
- Amazon Neptune
- Amazon Omics
- Amazon Prometheus Service
- Connect Health
- Amazon Elastic Compute Cloud
- Amazon EC2 Container Service
- Amazon Lightsail
- AWS Elemental MediaLive
- Amazon SageMaker Service
- AWS Sign
- Amazon Bedrock
- Amazon CloudWatch
- Amazon Elastic Compute Cloud
- odb
- AWS Outposts
- AWS Compute Optimizer
- Cost Optimization Hub
- AWSDeadlineCloud
- AWS DevOps Agent Service
- AWS Elemental MediaPackage v2
- Application Migration Service
- CloudWatch Observability Admin Service
- Amazon Omics
- Tax Settings
๐น IAM managed policy changes
-
No changes this week.
โ CloudFormation resource changes
๐ฎ Amazon Linux vulnerabilities
- CVE-2026-11526: perl-GD command injection via 2-arg open() (8.4)
- CVE-2026-49839: jq heap buffer overflow via --rawfile
- CVE-2026-47729: Squid OOB read in FTP gateway
- CVE-2026-48914: QEMU virtio-blk OOB write / DoS
- CVE-2026-11791: 389-ds use-after-free on schema reload (DoS)
- CVE-2026-50012: Squid cache-digest heap overflow (8.1)
- CVE-2026-47167: Vim Ruby code injection in cucumber plugin
- CVE-2026-53702: GStreamer/GTK H.265 stack overflow
- CVE-2026-52858: Vim Python omni-completion code execution
- CVE-2026-44494: PCP/Axios prototype-pollution gadget enables MITM (8.7)
- CVE-2026-52859: Vim terminal scrollback OOB read (DoS)
- CVE-2026-11850: krb5 LDAP KDB heap OOB read
- CVE-2026-47162: Vim netrw Vimscript code injection
- CVE-2026-52860: Vim Python omni-completion code execution
- CVE-2026-53701: GStreamer H.266 OOB write
- CVE-2026-11774: 389-ds SASL integer overflow, RCE/DoS (7.6)
- CVE-2026-49219: ImageMagick policy bypass via symlink
- CVE-2026-48994: ImageMagick MAT decoder heap overflow (32-bit)
- CVE-2026-52726: python-dulwich submodule path traversal RCE (8.8)
- CVE-2026-53463: ImageMagick NULL deref in distort
- CVE-2026-49218: ImageMagick DCM bad-dimensions crash
- CVE-2026-48733: ImageMagick infinite loop in subimage-search
- CVE-2026-53462: ImageMagick use-after-free crash
- CVE-2026-10846: ldns UDP resolver off-path cache poisoning
- CVE-2026-48734: ImageMagick MVG stack overflow
- CVE-2026-53461: ImageMagick ICON decoder OOB write
- CVE-2026-53460: ImageMagick OOM via missing memory cap (7.5)
- CVE-2026-53464: ImageMagick memory leak in option parser
- CVE-2026-6893: dracut DHCP option command injection, root RCE (8.8)
- CVE-2026-11837: ansible authorized_key symlink local privesc
- CVE-2026-48724: ImageMagick Floyd-Steinberg heap over-write
- CVE-2026-53689: libnfs integer overflow via crafted NFS server
- CVE-2026-53465: ImageMagick SF3 encoder heap over-write
- CVE-2026-11884: 389-ds heap overflow in objectclass serialization
- CVE-2026-45491: .NET link-following local tampering
- CVE-2026-11789: 389-ds SMD5 buffer over-read crash
- CVE-2026-42769: OpenSSL CMP root CA cert validation bypass
- CVE-2026-45445: OpenSSL AES-OCB IV reuse breaks confidentiality (7.4)
- CVE-2026-11787: 389-ds heap over-read in filter parsing
- CVE-2026-34180: OpenSSL ASN.1 large-element heap over-read
- CVE-2026-45446: OpenSSL AES-SIV/GCM-SIV empty-ciphertext forgery
- CVE-2026-34181: OpenSSL PKCS#12 PBMAC1 cert/key forgery (7.4)
- CVE-2026-11786: 389-ds LDIF parser OOB read on import
- CVE-2026-11790: 389-ds PBKDF2 unbounded iterations DoS
- CVE-2026-11785: 389-ds SSO token stack address disclosure
- CVE-2026-11793: 389-ds stack overflow in reversible-pw parsing
- CVE-2026-11792: 389-ds audit log heap overflow
- CVE-2026-42771: OpenSSL OOB read validating crafted email (DoS)
- CVE-2026-9698: perl-DBI error-buffer overflow
- CVE-2026-42770: OpenSSL DHX small-subgroup private key recovery
- CVE-2026-35188: OpenSSL OCSP-stapling double-free (DoS)
- CVE-2026-11623: tmux use-after-free in image_free
- CVE-2026-42765: OpenSSL OCSP partial-chain NULL deref (DoS)
- CVE-2026-34183: OpenSSL QUIC PATH_CHALLENGE memory exhaustion (7.5)
- CVE-2026-34182: OpenSSL CMS AuthEnvelopedData validation flaw (7.4)
- CVE-2026-42764: OpenSSL QUIC invalid-token NULL deref (DoS)
- CVE-2026-44170: MariaDB CONNECT engine REST command injection (7.5)
- CVE-2026-45591: ASP.NET Core resource exhaustion DoS (7.5)
- CVE-2026-45490: .NET improper authorization local privesc (7.8)
- CVE-2026-48163: MariaDB galera SST parameter injection RCE (8.0)
- CVE-2026-11788: 389-ds NULL alloc-failure crash (DoS)
- CVE-2026-45447: OpenSSL PKCS#7 verify use-after-free, possible RCE (8.1)
- CVE-2026-44171: MariaDB mbstream path traversal on extract
- CVE-2026-7383: OpenSSL ASN1_mbstring integer overflow heap overflow
- CVE-2026-42768: OpenSSL CMS/PKCS7 Bleichenbacher oracle
- CVE-2026-44172: MariaDB big5 SQL injection via escape bypass
- CVE-2026-44173: MariaDB INTO OUTFILE without FILE privilege
- CVE-2026-48165: MariaDB galera SST shell command execution (8.0)
- CVE-2026-44169: MariaDB SHOW CREATE ROUTINE ignores roles
- CVE-2026-42767: OpenSSL CMP CRMF NULL deref (DoS)
- CVE-2026-44168: MariaDB mariabackup SST command injection (8.0)
- CVE-2026-9076: OpenSSL CMS PWRI heap over-read (DoS)
- CVE-2026-42766: OpenSSL password-CMS NULL deref (DoS)
- CVE-2026-42536: Apache httpd mod_xml2enc heap overflow
- CVE-2026-42535: Apache httpd mod_dav_fs property DB tampering
- CVE-2026-29167: Apache httpd mod_ldap use-after-free
- CVE-2026-34355: Apache httpd mod_proxy_html buffer overflow
- CVE-2026-29170: Apache httpd mod_proxy_ftp XSS
- CVE-2026-44186: Apache httpd mod_proxy_ftp infinite loop
- CVE-2026-34356: Apache httpd ProxyPassReverseCookie heap overflow
- CVE-2026-44185: Apache httpd OCSP buffer over-read
- CVE-2026-48913: Apache mod_http2 use-after-free
- CVE-2026-44119: Apache httpd .htaccess local file read
- CVE-2026-44631: Apache httpd config regex buffer underwrite
- CVE-2026-43951: Apache httpd mod_headers/mod_mime OOB read
- CVE-2026-11611: 389-ds content-sync DoS / teardown crashes
- CVE-2026-9669: Python bz2 decompressor reuse OOB write
๐บ AWS security bulletins
๐ฌ Security documentation changes
- ECS daemon tasks add pidMode/ipcMode sharing and PERFMON capability
- Amazon MQ ActiveMQ doc links moved to HTTPS
- Amazon MQ ActiveMQ doc links moved to HTTPS
- Amazon MQ ActiveMQ doc links moved to HTTPS
- Amazon MQ doc links moved to HTTPS, IAM URL typo fixed
- Amazon MQ notes OAuth2 needs JWKS endpoint connectivity in private brokers
- Amazon MQ RabbitMQ OAuth2 param renamed jwks_url to jwks_uri
- Bedrock docs fix data retention mode setting name for abuse detection
- Bedrock docs fix data retention mode setting name for abuse detection
- CLI adds --ssh-options for SSH configuration
- CLI adds --ssh-options for SSH configuration
- CLI adds --ssh-options for SSH configuration
- CLI adds --ssh-options for SSH configuration
- CloudShell docs add AWS Tools for PowerShell setup
- Direct Connect adds BGP TTL security (GTSM) troubleshooting
- HealthLake notes encryption config is fixed after data store creation
- HealthLake notes auth metadata is updatable post-creation
- HealthLake notes fine-grained authorization can be toggled post-creation
- HealthLake notes identity provider config is updatable post-creation
- ParallelCluster clarifies SSH KeyName removal in 3.15.0
- Secrets Manager bumps CDK version and Python 3.12 for rotation Lambdas
- SMS Voice adds Australia sender ID registration guidance
- Storage Gateway releases note security improvements
- Storage Gateway releases note security improvements
- WorkSpaces 2026.0 fixes smart card authentication
- Bedrock data retention docs add Fable 5 mandatory Anthropic data sharing
- Bedrock docs add refusal stop_details, note higher Fable 5 refusal rate
- CLI adds DNS resolution mode and failure message fields
- CLI adds DNS resolution mode and failure message fields
- CLI adds operatorAppUrl output field with HTTPS constraint
- CLI adds operatorAppUrl output field with HTTPS constraint
- CLI adds field constraints and mcpRoleArn IAM role docs
- CLI deprecates roleArn for mcpRoleArn, adds private connection params
- CLI adds DNS resolution mode and failure message fields
- CLI adds OCI integration IAM role and tenancy fields
- Connect adds Cases Export permission that auto-grants case view
- DocumentDB docs require TLS 1.2+ from 5.0.1 and 8.0
- DocumentDB docs require TLS 1.2+ from 5.0.1 and 8.0
- DocumentDB 5.0 release notes document a required security patch
- GovCloud docs expand AMS Accelerate limitations
- GovCloud notes EC2 Image Builder export-control restrictions
- VPC Flow Logs v11 restricts cross-account EC2 tag visibility