Issue #272
Monday · August 03, 2026
๐ฅ Palate Cleanser
Hugging Face has now published the day-by-day AWS-heavy technical timeline of the incident I mentioned last week.
A file-read bug leaked the worker pod's whole environment, secrets included, and a Jinja2 template injection gave code execution inside a production pod. From there the agent read the EC2 node role credentials off the instance metadata service and authenticated to the cluster API as the node itself. It then minted service account tokens for the Container Storage Interface (CSI) storage-driver pods, whose ClusterRole granted pod creation cluster-wide, and dropped a privileged pod that nothing in admission control was set to reject, stepping out to root on the node.
Apparently, this technique is not new. It is the EKS privilege escalation An Trinh and Duc Nguyen documented in April 2023, run end to end - pod reaches IMDS, IMDS hands over the node role, node role becomes a cluster identity via aws eks get-token, and the node then mints service account tokens for the pods it hosts. Three years old. Still the most reliable way out of a pod on any EKS cluster that never set the metadata hop limit to 1.
Unrelated, AWS published a service (un)availability update. Eleven services and features moved to maintenance on 30 July, bar IoT Device Defender Detect which gets until 31 August. Nine more inside SageMaker. Five more are sunsetting and two are already gone. Amazon Cognito Sync and Amazon Bedrock Agents Classic ๐ฑ are both on the maintenance list. Only ~300 more to go?
This issue is also available to share online. Got feedback? Tell us here.
๐ Chef's selections
by Scott Piper
Nebius, Crusoe, Vultr, Lambda Labs and DigitalOcean all rent GPUs, and all of them plus Cloudflare sell object storage you drive with the plain AWS CLI, just pointed at their endpoint with keys like Nebius's NAKI or Crusoe's CKIA instead of AKIA. Scott checked how much of your S3 knowledge survives the trip and the answer is not much, because on one clone get-bucket-policy returned a bucket listing dressed up as a policy and delete-bucket-policy deleted the bucket. Vultr, Crusoe and Lambda Labs cannot scope a key at all, so every key opens everything, and Vultr's API will hand back a secret that AWS would have shown you exactly once. Only Nebius and DigitalOcean log data plane events. I probably shouldn't get upset when AWS implements something inconsistently given how bad these things are at AWSifying stuff.
AgentCore or AgentSore: Cross-Agent Privilege Escalation in Bedrock AgentCore
Ori Hadad at Unit 42 published this in April and called it Agent God Mode. The Bedrock AgentCore starter toolkit auto-generates an execution role with wildcard resource scopes, so any agent can pull any other agent's container image, read or poison any other agent's memory, and invoke any interpreter or runtime in the account, the same wildcard habit I complained about in the old Bedrock Agents console builder last October, that time in the trust policy. Kennedy's post is openly a demo of Mitigant's attack emulation platform, which stands up a victim and an attacker agent, runs all four paths and tears it down in about four minutes, but the telemetry work is the reason to read it. AgentCore's data plane writes nothing to CloudTrail unless you enable Data Events, and even then the CreateEvent body arrives as HIDDEN_DUE_TO_SECURITY_REASONS, so you can prove someone wrote into another agent's memory but never see what they wrote.
A Security Analysis of Amazon S3 Vectors and Its Use in LLM Retrieval Pipelines
by Ioan Criste and Emanuel Ioniศฤ
Amazon S3 Vectors adds a vector bucket type to S3 that stores embeddings and answers similarity queries, so a RAG pipeline like Bedrock Knowledge Bases can fetch context without running a separate vector database. The store itself held up under testing, but nothing checks what the metadata on a vector actually says, so anyone who already holds s3vectors:PutVectors can rewrite the chunk text an LLM reads and forge the citation metadata so the answer cites a real, unmodified PDF that says something else. In their own AWS account one planted vector had a clinical assistant recommending 4 grams of metformin a day, double the safe maximum, citing the untouched hospital formulary. AWS reviewed it and called it working as designed, which is fair, and also means your knowledge base is only as safe as whoever holds PutVectors or PutVectorBucketPolicy.
๐ธ Sponsor shoutout
Most code shipped today is AI-generated and the triage queue grew to match. Pleri AI works out which findings are actually exploitable and submits the fix. See the platform and get a free assessment.
๐ฅ AWS security blogs
- 📢 Amazon Location Service adds Search Nearby support for GrabMaps in Southeast Asia
- 📢 Amazon CloudWatch announces managed Prometheus collectors
- 📢 AWS Managed Microsoft AD now supports Standard to Enterprise Edition upgrade
- 📢 Amazon EFS now supports cross-account Replication in AWS GovCloud (US)
- 📢 AWS IAM Identity Center extends multi-Region support to Identity Center directory
- 📢 Amazon GameLift Streams now supports Custom Aspect Ratio and Dynamic Resolution
- 📢 AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)
- Orca just-in-time access & AWS IAM Identity Center solve permission sprawl by Merin Eralil
- Add security context to operational investigations with AWS DevOps Agent and Wiz by Yuriy Prykhodko
- HIPAA Security Rule on AWS โ Technical Safeguards Implementation and Readiness Guidance by Abdul Javid
- Balancing speed and safety: A control framework for AI coding agents by Daniel Begimher
- Extend Amazon Inspector SBOM Generator with Plugins by Michael Long
- Amazon identifies North Korean hacker group behind open-source supply chain attacks by CJ Moses
- Secure your npm and pip package updates in Amazon Linux by Norbert Manthey
- AWS KMS or AWS CloudHSM: Choose the right key management solution by Derek Tumulak
- 2026 Phase 1a IRAP report is now available on AWS Artifact for Australian customers by Patrick Chang
- AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare by Eitav Arditti
- Announcing the Cloud Security Alliance on AWS Compliance Guide by Juan Rodriguez
๐ Reddit threads on r/aws
๐ค Dessert
Every machine-tracked change this week. Nobody else assembles this.
๐ง IAM permission changes
๐ช API changes
- Amazon Prometheus Service
- Amazon Bedrock Runtime
- AWS Billing
- AWS CloudFormation
- AmazonConnectCampaignServiceV2
- Amazon DataZone
- AWS Elemental Inference
- Amazon CloudWatch Logs
- AWS Marketplace Catalog Service
- AWS Outposts
- Amazon QuickSight
- Amazon Relational Database Service
- AWS Resilience Hub V2
- Amazon Bedrock AgentCore Control
- AWS Identity and Access Management
- Managed Streaming for Kafka
- AWS Lambda
- AWS Network Firewall
- PricingPlanManager
- Amazon SageMaker Service
- AWS Security Agent
- Amazon Elastic Compute Cloud
- Amazon GameLift Streams
- AWS Glue
- AWS IoT SiteWise
- AWS WAFV2
- Amazon Bedrock AgentCore Control
- TrustedAdvisor Public API
- AWS Account
- AWS Billing and Cost Management Data Exports
- AWS Clean Rooms Service
- AWS Clean Rooms ML
- Amazon EMR Containers
- AWS Glue
- Partner Central Account API
- Amazon QuickSight
- Amazon SageMaker Service
- AWS Security Agent
๐น IAM managed policy changes
- AWSResilienceHubResilienceTestingPolicy
- AWSResourceExplorerServiceRolePolicy
- AWSSupportPlansServiceRolePolicy
- AWS_ConfigRole
- AWSConfigServiceRolePolicy
- Billing
- AWSBillingReadOnlyAccess
- AmazonSageMakerInferenceServiceRolePolicy
- AmazonInspector2AmiScanServiceRolePolicy
- PricingPlanManagerReadonlyAccess
- PricingPlanManagerFullAccess
- CloudFrontFullAccess
- AWSApplicationMigrationNetworkMigrationMultiAccount
- SageMakerStudioProjectUserRolePolicy
- ROSANodePoolManagementPolicy
- ROSAControlPlaneOperatorPolicy
- AWSWAFFullAccess
- BedrockAgentCoreFullAccess
- AWSTransformSecurityAgentExecutorAccess
- AWSTransformInfrastructureExecutorAccessEC2
- AWSTransformInfrastructureExecutorAccessBatch
- ROSAKarpenterControllerPolicy
โ CloudFormation resource changes
No resource updates this week.
๐ฎ Amazon Linux vulnerabilities
- CVE-2026-66402: FreeRDP TLS certificate identity validation weaknesses
- CVE-2026-58041: Node.js SQLite iterator replay can re-execute writes
- CVE-2026-18217: Keycloak SAML redirect binding accepts attacker parameters
- CVE-2026-16105: Keycloak admin REST API name endpoints skip authorization
- CVE-2026-58042: Node.js dns.resolveAny aborts the process, DoS
- CVE-2026-6949: Samba TSIG name compression crashes the DNS server
- CVE-2026-64607: Apache HttpClient leaks connections on bad Content-Type
- CVE-2026-53583: libgit2 inverted IP SubjectAltName check in OpenSSL backend
- CVE-2026-18208: Keycloak OIDC token introspection flaw
- CVE-2026-18209: Keycloak OIDC flow skips a security check
- CVE-2026-53587: libgit2 heap out-of-bounds read in smart HTTP transport
- CVE-2026-58045: Node.js zlib sync APIs crash on spoofed TypedArray length
- CVE-2026-53585: libgit2 unbounded memory allocation via delta size header
- CVE-2026-18218: Keycloak client token revocation misses tokens
- CVE-2026-56846: Node.js HTTP/2 retained headers bypass maxSessionMemory
- CVE-2026-18211: Keycloak secure-client-uris policy executor flaw
- CVE-2026-18215: Keycloak Microsoft tenant restriction can be bypassed
- CVE-2026-58044: Node.js header truncation enables request smuggling
- CVE-2026-15722: 389 Directory Server stack buffer overflow in replication
- CVE-2026-18358: gnome-remote-desktop RDP pre-auth connection flood, DoS
- CVE-2026-11770: 389 Directory Server unauthenticated LDAP filter injection
- CVE-2026-58221: Samba AD authenticated LDAP domain takeover, CVSS 8.8
- CVE-2026-18321: NTPsec Zyfer refclock buffer overflow crashes ntpd
- CVE-2026-58224: Samba CTDB protocol bounds checking issues
- CVE-2026-18203: Keycloak group policy over-extends permissions to child groups
- CVE-2026-53584: libgit2 submodule path traversal
- CVE-2026-53586: libgit2 follows offsite redirects then prompts for credentials
- CVE-2026-58039: Node.js process.report writes outside allow-fs-write
- CVE-2026-56848: Node.js HTTP/2 heap use-after-free
- CVE-2026-9672: PHP gd image handling flaw
- CVE-2026-16531: PCP pmproxy path traversal via crafted hostname
- CVE-2026-58218: Samba DNS signing DoS via TKEY name cache exhaustion
- CVE-2026-16527: PCP pmproxy store endpoint access control bypass
- CVE-2026-58216: Samba authenticated user can crash the KDC
- CVE-2026-18369: Dogtag PKI ACME validator follows unvalidated redirects
- CVE-2026-56850: Node.js HTTPS agent reuses mTLS client identities
- CVE-2026-17543: PHP backslash escaping allows trivial SQL injection, CVSS 9.8
- CVE-2026-58222: Samba AD LDAP filter injection leaks protected attributes
- CVE-2026-60074: Perl Date::Manip returns corrupted dates from non-ASCII digits
- CVE-2026-62363: ImageMagick heap buffer over-write in the fx engine
- CVE-2026-64685: ImageMagick BGR decoder misses end-of-data check
- CVE-2026-16526: PCP linux_sockets unsecured internal connection, privesc
- CVE-2026-60075: Perl Date::Manip CPU exhaustion via regex backtracking
- CVE-2026-56847: Node.js trace_events writes logs outside allow-fs-write
- CVE-2026-18140: aws-smithy-json uncontrolled recursion, unauthenticated DoS
- CVE-2026-7260: PHP phar circular symlinks exhaust the stack
- CVE-2026-68499: re2 Node bindings DoS on global pattern match
- CVE-2026-16524: PCP linux_sockets PMDA command injection
- CVE-2026-62946: ImageMagick DoS on extremely large input
- CVE-2026-58043: Node.js permission model over-grants filesystem access
- CVE-2026-17544: PHP bccomp out-of-bounds write corrupts stack and heap, CVSS 8.6
- CVE-2026-16529: PCP integer overflow in __pmGetPDU blinds monitoring
- CVE-2026-13379: OpenVPN Windows service DNS state pollution or crash
- CVE-2026-62343: ImageMagick heap over-write via user supplied morphology kernel
- CVE-2026-58040: Node.js TLS session reuse skips hostname verification
- CVE-2026-16530: PCP pmproxy flaw in pmLogLoadInDom
- CVE-2026-15157: undici uses an unvalidated blob type as Content-Type
- CVE-2026-55995: open-iscsi double free, MITM DoS
- CVE-2026-44943: open-iscsi path traversal creates root-owned files, CVSS 8.6
- CVE-2026-13697: undici cache interceptor mishandles private directives
- CVE-2026-8348: QEMU 9pfs does not limit simultaneous xattr FIDs
- CVE-2026-15705: QEMU usbredir use-after-free
- CVE-2026-63319: QEMU usbredir peer can reset max_packet_size to zero
- CVE-2026-56389: GNU Bison runs arbitrary programs during HTML report generation
- CVE-2026-16729: undici setCookie does not fully sanitize attributes
- CVE-2026-14643: undici mishandles whitespace in Cache-Control directives
- CVE-2026-18220: binutils BFD DLX backend out-of-bounds write
- CVE-2026-15578: QEMU VNC server does not validate pixel format maxima
- CVE-2026-16728: undici retry can deliver a body that mismatches Content-Length
- CVE-2026-16043: QEMU sysbus-xhci out-of-bounds heap access, CVSS 8.2
- CVE-2026-9238: QEMU 9pfs readdir allows unbounded allocation
- CVE-2026-18201: Keycloak identity provider admin API flaw
- CVE-2026-56390: GNU Bison accepts unrestricted grammar-defined output paths
- CVE-2026-44944: open-iscsi lets unprivileged users use the iscsiuio socket
- CVE-2026-61475: QEMU VNC out-of-bounds write marking dirty bitmap rows
- CVE-2026-18207: Keycloak checks group membership by name instead of ID
- CVE-2026-13346: pip doubly-encoded URLs install files to arbitrary paths
- CVE-2026-62430: Xen unlocked CMOS index cache allows out-of-bounds read
- CVE-2026-42494: Xen libfsimage iso9660 directory walk trusts on-disk lengths
- CVE-2026-18107: CRIU rseq handling lets a container process escape
- CVE-2026-18047: Dogtag PKI ACME admin endpoint bypass via URL suffix
- CVE-2026-17072: GStreamer heap out-of-bounds read parsing FLAC headers
- CVE-2026-66753: tiny-http HTTP header injection via CR and LF
- CVE-2026-16313: sg3_utils sg_inq exports unsanitized control characters
- CVE-2026-62434: Xen Populated on Demand page reclaim corrupts memory state
- CVE-2024-14041: Bouncy Castle ML-KEM non-constant-time division leaks secrets
- CVE-2026-66299: Apache Tomcat WebSocket chat example resource exhaustion
- CVE-2026-62426: Xen sysctl lock unfairness allows guest DoS
- CVE-2026-62427: Xen platform-op lock unfairness allows guest DoS
- CVE-2026-6879: Python ElementTree XPath index predicates go quadratic
๐บ AWS security bulletins
- Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
- CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
- CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
- CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers