Issue #273
Monday · August 10, 2026
🥖 Palate Cleanser
Hacker summer camp has just wrapped up in Vegas. Hope you had fun for those who attended. There were quite a few AWS-related talks, at DEF CON Cloud Village and elsewhere, but not much of the content is online yet except for a couple of decks. Hopefully it starts rolling in next week.
While everyone was in Vegas, someone pushed a malicious commit to the keyv repository and by the end of the day a self-propagating worm had hundreds of npm packages, the cacheable ecosystem included. It sux for us because the malware scrapes STS account metadata, Secrets Manager values across seventeen regions, SSM Parameter Store, and, on Linux runners with sudo, GitHub Actions secrets out of process memory. If a build host ran an install that day, rotate everything that host's role could reach, not just the npm token.
Luckily AWS published eight security bulletins to keep us entertained. Seven of them are about agent tooling. Bedrock AgentCore's harness failed to validate input. Kiro's IDE and CLI resolved executables out of an untrusted project directory on Windows, which is nowhere near Kiro's first code execution bug this year. Three separate MCP servers shipped by AWS itself broke: AWS Transform on path handling, DocumentDB on authorization in its aggregation pipeline tool, and Amazon MQ, which hands over broker credentials and OAuth tokens if you prompt inject it. Strands Agents Tools managed two, an insecure direct object reference in the memory tools and a prompt injection that walks straight through the shell tool's consent gate. The eighth is SSH host key verification disabled in the AWS CLI EMR helpers, which is almost nostalgic.
This issue is also available to share online. Got feedback? Tell us here.
📋 Chef's selections
OffGuard: Breaking the Most Popular AI Gateway from Auth Bypass to Cloud Compromise (Slides)
by Yaara Shriki
LiteLLM, the open source proxy many orgs park in front of Bedrock and friends, will fetch any URL an admin configures and hand back the response, instance metadata at 169.254.169.254 included. IMDSv2 is supposed to stop exactly that, but the pass-through strips a configured prefix before forwarding headers, so x-pass-X-aws-ec2-metadata-token arrives as the real header and the instance role credentials come straight back. Creating that route needs the admin master key, but it's included in the quickstart guides, tutorials and Docker Compose files as sk-1234.
by Jenko Hwong and Chris Ryan
CloudShell hands you three sessions that are not the same thing: the console session, an IAM API session minted by STS token exchange, and the terminal websocket. Revoke the API token mid-incident and the websocket carries on regardless. Jenko and Chris reversed the private CloudShell REST protocol to automate the whole thing at scale, then made themselves at home with a second uid 0 account, and root-owned files in $HOME that survive a container reset. Seems bad for incident response.
💸 Sponsor shoutout
Most code shipped today is AI-generated and the triage queue grew to match. Pleri AI works out which findings are actually exploitable and submits the fix. See the platform and get a free assessment.
🥗 AWS security blogs
- 📢 Amazon Cognito now available as a skill in the Agent Toolkit for AWS
- 📢 AWS IAM Identity Center supports one-click multi-Region option for new organization instances
- 📢 AWS WAF now supports a Salt Security managed rule group for API and MCP threat detection
- 📢 AWS Security Agent now supports email-based MFA for penetration testing
- 📢 Amazon Quick supports multi-dataset analytical capabiity
- 📢 Amazon DynamoDB now supports real-time vector search
- 📢 AWS IAM Identity Center makes management of AWS account access optional for new organization instances
- 📢 AWS Security Hub Extended adds supply chain security as its 10th category
- 📢 Amazon GameLift Streams now supports sharing streams with stream URLs
- 📢 AWS Lambda Provisioned Mode for Amazon SQS event source mappings now supports up to 10,000 event pollers
- 📢 AWS WAF now supports Miggo Security managed rule groups for emerging threats and AI/ML application protection
- How to authenticate customers during chat with Amazon Connect Customer by Naga Bhargav
- Hyundai AutoEver: Building a multi-tenant generative AI sandbox and production AIOps on Amazon Bedrock by Min-Oh Heo
- Reintroducing Network Firewall Proxy for Secure Egress Connectivity by Tom Adamski
- A decade of enterprise identity in the cloud with AWS Managed Microsoft AD by Vladimir Provorov
- Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access by Hetal Kolekar
- Automate certificates with ACME support in AWS Certificate Manager by Anthony Harvey
- Route Amazon Bedrock Guardrails interventions to Amazon Security Lake by Dhananjay Karanjkar
- Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale by Maria Gutovsky
- AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows by Chet Kapoor
- From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management by Kiran Dongara
- Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available by Will Black
🍛 Reddit threads on r/aws
🤖 Dessert
Every machine-tracked change this week. Nobody else assembles this.
🧁 IAM permission changes
🍪 API changes
- Amazon Connect Service
- Amazon Elastic Compute Cloud
- Amazon HealthLake
- AWS Elemental MediaPackage v2
- AWS MediaTailor
- Amazon SageMaker Service
- AWS Security Agent
- Agent Registry Control
- Agent Registry
- Auto Scaling
- AWS Backup
- Amazon Bedrock AgentCore Control
- Amazon Bedrock AgentCore
- AWS Device Farm
- Amazon Elastic Compute Cloud
- Amazon GameLift
- Managed Streaming for Kafka
- Amazon CloudWatch Logs
- AWS Marketplace Agreement Service
- AWS Marketplace Discovery
- AWS MediaTailor
- Amazon Simple Storage Service
- Amazon SageMaker Service
- AWS SecurityHub
- AWS End User Messaging Social
- AWS Certificate Manager Private Certificate Authority
- Amazon Bedrock AgentCore Control
- AWSDeadlineCloud
- Amazon EC2 Container Service
- AWS Glue
- Amazon DynamoDB
- Amazon Elastic Compute Cloud
- Inspector2
- Partner Central Selling API
- AWS Single Sign
- Amazon WorkSpaces
- AWS Direct Connect
- Amazon EKS Auth
- AWS Elemental MediaConvert
- AWS Network Firewall
- CloudWatch Observability Admin Service
- Timestream InfluxDB
🍹 IAM managed policy changes
- AWSManagedSettingsAdminAccess
- AWSBudgetsSpendLimitMemberRolePolicy
- AWSApplicationMigrationFSxProxyPolicy
- AWSManagedBudgetsSpendLimitManagementAccess
- AmazonSageMakerJobRuntimeAccess
- CloudWatchAutomaticDashboardsAccess
- AmazonODBReadOnlyAccess
- AmazonODBNetworkAdmin
- AmazonODBExadataInfrastructureAdmin
- AmazonODBAutonomousVmClusterAdmin
- AWSManagedSettingsAdminAccess
- AgentRegistryReadOnlyAccess
- AgentRegistryFullAccess
- AWSBackupAccessPointOperatorAccess
- AWSTransformServerMigrationAgentPolicy
- AWSTransformNetworkMigrationAgentPolicy
- AWSTransformLandingZoneAgentPolicy
- AWSAgentRegistryServiceRolePolicy
- BedrockAgentCoreRuntimeInstancesOperatorRolePolicy
- AWSIAMRoleManagerServiceRolePolicy
- BatchServiceRolePolicy
- AIDevOpsConstellationAccessPolicy
- BedrockAgentCoreRuntimeInstancesInstanceRolePolicy
- BedrockAgentCoreRuntimeInstancesOperatorRolePolicy
- AWSBedrockAgentCoreRuntimeInstancesServiceRolePolicy
- AmazonHealthLakeReadOnlyAccess
- EC2FastLaunchFullAccess
- AWSServiceCatalogAdminFullAccess
- AWSWellArchitectedAgentResourceScanningServiceRolePolicy
- AWSServiceCatalogEndUserFullAccess
- AmazonBedrockMantleInferenceAccess
- AmazonBedrockLimitedAccess
- AmazonBedrockFullAccess
- AmazonBedrockMantleFullAccess
- AmazonTimestreamInfluxDBFullAccessWithoutMarketplaceAccess
- AmazonTimestreamInfluxDBFullAccess
- SageMakerStudioDomainExecutionRolePolicy
- AWSElasticBeanstalkServiceRolePolicy
- AmazonBedrockWebSearchReadOnly
- AmazonBedrockWebSearchFullAccess
- AmazonBedrockExternalWebSearchReadOnly
- AmazonBedrockExternalWebSearchFullAccess
- AWSApplicationMigrationFullAccess
☕ CloudFormation resource changes
No resource updates this week.
🎮 Amazon Linux vulnerabilities
- CVE-2026-44950: libXfont2 heap overflow from a malicious font server (8.1)
- CVE-2026-59679: libXfont2 out-of-bounds access from a malicious font server (8.1)
- CVE-2026-62292: libheif out-of-bounds read in tile slicing
- CVE-2026-62289: libheif integer underflow in clap transform
- CVE-2026-42170: GIMP DDS loader heap overflow on crafted files
- CVE-2026-61477: libvirt newline injection into dnsmasq config
- CVE-2026-18938: p11-kit integer overflow under-allocates on 32-bit
- CVE-2026-15816: dracut runs unquoted DHCP ROOT_PATH data as shell
- CVE-2026-71556: amazon-ssm-agent go-git symlinks escape the worktree
- CVE-2026-71847: Ruby JSON use-after-free in the resumable parser
- CVE-2026-19079: policycoreutils fixfiles relabel TOCTOU race
- CVE-2026-71557: amazon-ssm-agent go-git path traversal via ref names
- CVE-2026-7867: udisks2 local root via as-user mount spoofing, public exploit
- CVE-2026-32327: apr-util XML stack recursion DoS
- CVE-2026-71497: jsoup tag confusion on malformed tag names
- CVE-2026-18967: Keycloak ignores SAML OneTimeUse, assertions replay
- CVE-2026-34501: apr-util redis client heap overflow (8.2)
- CVE-2026-34502: apr-util memcached client heap overflow
- CVE-2026-71554: python-h2 duplicate Host headers enable smuggling
- CVE-2025-49506: apr-util password compare is not constant time
- CVE-2026-18649: GStreamer RTP depayloader reassembly DoS
- CVE-2026-34191: apr-util Oracle DBD SQL injection (9.1)
- CVE-2026-71227: libkcapi AIO reuse hangs in a non-terminating loop
- CVE-2026-18839: popt integer underflow formatting help text
- CVE-2026-71226: libkcapi memory corruption via undrained AIO
- CVE-2026-54876: OpenSSL OCSP response leaks TLS client memory
- CVE-2026-71313: rclone remote filenames escape the local backend path
- CVE-2026-18103: dhcp OMAPI crafted lease creation request
- CVE-2026-16443: Keycloak SAML import silently disables signature checks
- CVE-2026-15573: Keycloak PathMatcher URI normalization auth bypass (8.1)
- CVE-2026-16071: Keycloak LDAP lookups miss DN validation
- CVE-2026-16102: Keycloak DCR mappers write to internal claims (8.1)
- CVE-2026-16100: Keycloak metrics labels take raw user input
- CVE-2026-71225: libkcapi reuses the IV on large one-shot operations
- CVE-2026-68743: SSSD PAM responder out-of-bounds read
- CVE-2026-18809: Firefox for Android information disclosure
- CVE-2026-51401: Vim code execution via vms_fixfilename()
- CVE-2026-18739: popt off-by-one corrupts internal state
- CVE-2026-68744: SSSD NSS responder leaks uninitialised heap
- CVE-2026-68494: jackson-core number length fix was incomplete
- CVE-2026-70367: stunnel SOCKS SSRF bypass via IPv4-mapped IPv6
- CVE-2026-51400: Vim code execution via vms_fixfilename() (7.8)
- CVE-2026-18401: jackson-core async parser ignores maxNumberLength
- CVE-2026-10050: Jetty digest auth mangles non-Latin-1 passwords
- CVE-2026-42169: GIMP APNG loader heap overflow
- CVE-2026-70368: stunnel out-of-bounds read on oversized log lines
- CVE-2026-18569: Keycloak backchannel logout accepts unsigned requests
📺 AWS security bulletins
- CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
- CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows
- CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
- CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
- CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
- CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
- CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
- CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools