Issue #277
Monday · September 07, 2026
๐ฅ Palate Cleanser
fwd:cloudsec Europe is on today and tomorrow in London, and I'm sure it will be an awesome event. Both days are streamed if you didn't make it over, day one and day two. Selfishly, what I'm really looking forward to is the flurry of blog posts that follows.
Act Security bought Cloud Copilot and David Kerber went with it. If you use iam-collect, iam-lens, iam-simulate or iam-expand, they moved to the act-security-labs org on 1 September and they are still AGPL-3.0. They are bundled now as Amphi with a browser UI and no signup. The small loss is that iam.cloudcopilot.io now 302s to the corporate site, so the independent blog is gone, and the posts I ran on Policy Tester in issue 192, fantastic AWS policies in 229 and testing S3 ABAC with iam-lens in 240 all live there now.
Reminder that nominations for the Top 10 AWS Security Research of 2026 close on 30 September. No login, no email address, self-nominations welcome, and I would much rather sift through too many than miss the good stuff. Go put something in.
This issue is also available to share online. Got feedback? Tell us here.
๐ Chef's selections
Reading other AWS accounts' SQL on Amazon Athena
by Act Research
Athena, the query service for S3, has an engine called Trino. Trino ships a system.runtime.queries table that lists recently executed queries, and on shared infrastructure "recently executed" means everybody's. Asking for the system catalog inside the SQL gets you "Queries of this type are not supported", but nobody was checking the same request's QueryExecutionContext, so you leave the catalog out of the SQL, pass Catalog=system as a parameter alongside it, and the query runs. What comes back is other tenants' actual query text, which means their account IDs and whatever they inlined into a WHERE or an INSERT. Across 200 runs by Act Security, 2,590 of 2,794 rows belonged to somebody else, and in a second round 102 of 109 runs caught at least one other account. It was reported on 6 August 2026, the call was disabled on the 8th, and every region fixed by the 10th, which is genuinely fast work. No CVE or bulletin though? However, AWS did publish a bulletin last month for an Athena federated connector template that leaked Secrets Manager secrets in your own account. ๐คท
Password spraying campaign targets AWS root user accounts across 150+ organizations
From 24 July to 23 August somebody worked through the root user of more than 150 organisations, a median of two attempts each and up to eight, proxied through hosting and residential IPs across a spread of countries and ASNs. Apparently nothing worked. A failed root ConsoleLogin requires the root account's email address, so whoever this is either already holds a list of root emails or found them by grinding through candidates. I wonder how big the full attack was outside of DD's visibility. Root MFA has been mandatory since June 2025 but you should still be alerting on ConsoleLogin with userIdentity.type of Root, and if you have not moved to centralized root access with short-lived AssumeRoot sessions and an SCP shutting the rest down, this is the nudge. Neither of those covers your management account root though, which still needs its own answer.
๐ธ Sponsor shoutout
Most code shipped today is AI-generated and the triage queue grew to match. Pleri AI works out which findings are actually exploitable and submits the fix. See the platform and get a free assessment.
๐ฅ AWS security blogs
- 📢 AWS Transfer Family SFTP Connectors now support continuing file transfers during credential rotation
- 📢 Amazon WorkSpaces Applications adds support for NVIDIA Blackwell GPU instances
- 📢 Amazon Linux 2027 is now available in public preview
- 📢 AWS Backup now supports protecting more than 1,000 Amazon S3 buckets per account
- 📢 Amazon Cognito now supports machine-to-machine authorization without a user pool domain
- 📢 Automated Security Response on AWS adds AI Toolkit for custom remediations
- Say Hello to 158 New AWS Competency and MSP Partners Added in August by Nick Paris
- Aligning AWS to MPA security best practices for media archives โ Part 3 by Jakob Rosinski
- Aligning AWS to MPA security best practices for media archives โ Part 1 by Jakob Rosinski
- Reduce Traffic Interruptions with Gateway Load Balancer TCP Reset by Donathan Ratcliffe
- Implementing encryption in transit across connectivity patterns with VPC Encryption Controls by Rohit Aswani
- AWS expands its Defending Digital Campaigns offering for the 2026 election cycle by Leo Zhadanovsky
- How to secure communications beyond encryption with AWS Wickr by Chris OโRourke
- OSPAR 2026 report now available with 167 services in scope by James Chang
- Incident response guide for AWS CloudTrail investigations โ Part 2 by Oscar Diaz
- Incident response guide for AWS CloudTrail investigations โ Part 1 by Oscar Diaz
- Managing identity source transition for AWS IAM Identity Center by Xiaoxue Xu
- Agentic security: Detection and response at machine speed by Gee Rittenhouse
- We invited a direct competitor into Security Hub Extended. Hereโs why. by Michael Fuller
- Automate IAM Identity Center governance with continuous discovery and reporting by Jonathan Nguyen
๐ Reddit threads on r/aws
๐ค Dessert
Every machine-tracked change this week. Nobody else assembles this.
๐ง IAM permission changes
๐ช API changes
- Amazon Bedrock
- Amazon Elastic Compute Cloud
- AWS MediaTailor
- Service Quotas
- Amazon Bedrock AgentCore Control
- Amazon Bedrock AgentCore
- Amazon Connect Service
- Elastic Disaster Recovery Service
- Amazon EC2 Container Service
- Amazon Elastic VMware Service
- Amazon GuardDuty
- AWS End User Messaging Social
- Amazon Transcribe Service
- AWS Transfer Family
- Amazon AppIntegrations Service
- Amazon Elastic Compute Cloud
- AWS Elemental MediaLive
- Application Migration Service
- odb
- Amazon SageMaker Feature Store Runtime
- Amazon SageMaker Service
- Amazon GuardDuty
- AWS IoT SiteWise
- Amazon Kinesis
- AWS Lambda
- Amazon Lightsail
- AWS Marketplace Agreement Service
- AWS Marketplace Discovery
- AWS Elemental MediaConvert
- Amazon Simple Email Service
- Tax Settings
- Agent Registry
- Agent Registry Control
- Agent Registry
- Amazon Connect Service
- Amazon Connect Customer Profiles
- AWS DevOps Agent Service
- Managed Streaming for Kafka Connect
- Amazon Kinesis
- Amazon Pinpoint SMS Voice V2
- Amazon QuickSight
- Amazon SageMaker Service
- AWS Support
- Amazon Workspaces Instances
๐น IAM managed policy changes
- AmazonODBReadOnlyAccess
- AmazonODBNetworkAdmin
- AmazonODBFullAccess
- AmazonODBExascaleVmClusterAdmin
- AmazonODBExascaleStorageVaultAdmin
- AmazonODBExadataVmClusterAdmin
- AmazonODBExadataInfrastructureAdmin
- AmazonODBAutonomousVmClusterAdmin
- AmazonODBAutonomousDatabaseAdmin
- SageMakerStudioProjectRoleMachineLearningPolicy
- AWSQuickSetupPatchPolicyDeploymentRolePolicy
- AWSCloud9ServiceRolePolicy
- BedrockAgentCoreFullAccess
- AmazonMQFullAccess
- AWSForWordPressPluginPolicy
- AWSResourceExplorerServiceRolePolicy
- AmazonAppStreamServiceAccess
- DataScientist
- AWSTransformInfrastructureExecutorAccessEC2
- AWSTransformInfrastructureExecutorAccessBatch
- AmazonECS_FullAccess
- BedrockAgentCoreFullAccess
- FinOpsAgentAgentPolicy
- AWSAccountSettingsManagementRole
- AWSTransformServerMigrationAgentPolicy
- AWSTransformNetworkMigrationAgentPolicy
- AWSTransformLandingZoneAgentPolicy
- CloudWatchNetworkFlowMonitorTopologyServiceRolePolicy
- AWSManagedSettingsAdminAccess
- AgentRegistryFullAccess
โ CloudFormation resource changes
๐ฎ Amazon Linux vulnerabilities
- CVE-2026-81738: OpenVPN Windows off-by-one stack overflow
- CVE-2026-84732: OpenVPN unspecified DoS
- CVE-2026-78221: OpenVPN Windows service buffer overflow
- CVE-2026-82312: OpenVPN Windows local DoS via NULL DACL
- CVE-2026-85498: polkit agent helper OOB read
- CVE-2026-65165: pcp/Slurm job step accounting flaw
- CVE-2026-84226: OpenVPN Windows netsh path hijack privesc
- CVE-2026-84471: OpenVPN unspecified DoS
- CVE-2026-78043: OpenVPN Windows service path traversal
- CVE-2026-84256: OpenVPN Windows command injection (CVSS 8.1)
- CVE-2026-80255: curl drops cookie Secure flag on tab
- CVE-2026-84890: Node.js undici unbounded decompression DoS
- CVE-2026-76925: Flatpak SystemHelper TOCTOU privesc
- CVE-2026-84383: libheif heap buffer overflow
- CVE-2026-85534: libsoup HTTP/2 client DoS
- CVE-2026-65109: pcp/Slurm slurmstepd deletes files outside spool
- CVE-2026-80231: curl reuses HTTPS connection across CA settings
- CVE-2026-85505: FreeIPMI ipmi-oem stack OOB read
- CVE-2026-80229: curl pooled TLS connection UAF
- CVE-2026-85197: libsoup HTTP/2 client UAF
- CVE-2026-18924: curl HTTP/2 server push UAF
- CVE-2026-85014: Node.js undici WebSocketStream crash DoS
- CVE-2026-19931: curl reuses Negotiate-authenticated connection
- CVE-2026-84933: Node.js undici caches Set-Cookie in shared cache
- CVE-2026-82208: curl wolfSSL cached CA store overrides callback
- CVE-2026-81666: Corosync integer overflow on 32-bit hosts
- CVE-2026-85218: BlueZ AVRCP stack buffer overflow
- CVE-2026-85509: FreeIPMI FRU stack buffer overflow
- CVE-2026-84450: libheif OOB read
- CVE-2026-84961: Node.js undici drops TLS verification callback
- CVE-2026-84947: Node.js undici dump interceptor DoS
- CVE-2026-65139: pcp/Slurm unsafe slurmdbd queries (CVSS 8.1)
- CVE-2026-85024: Node.js undici WebSocket inflate crash DoS
- CVE-2026-18149: Node.js undici retry handler hang
- CVE-2026-82209: curl misses public suffix cookie check
- CVE-2026-65108: pcp/Slurm slurmstepd stack overflow (CVSS 8.8)
- CVE-2026-85507: FreeIPMI ipmi-oem stack buffer overflow
- CVE-2026-85504: FreeIPMI Fujitsu SEL stack overflow (CVSS 8.8)
- CVE-2026-19534: Node.js undici WebSocket handshake crash DoS
- CVE-2026-71223: gfs2-utils integer overflow heap OOB write
- CVE-2026-85508: FreeIPMI ipmi-oem stack buffer overflow
- CVE-2026-81665: Corosync totempg heap buffer overflow
- CVE-2026-85506: FreeIPMI ipmi-oem stack buffer overflow
- CVE-2026-65138: pcp/Slurm slurmd heap OOB read and crash
- CVE-2026-84451: libheif OOB read
- CVE-2026-13608: curl LDAP SASL handshake auth bypass
- CVE-2026-80230: curl skips public key pinning check
- CVE-2026-85046: Node.js V8 type confusion RCE (CVSS 8.8)
- CVE-2026-85090: FreeRDP heap OOB read in AVC444 decode
- CVE-2026-71220: gfs2-utils gfs2_edit stack OOB write
- CVE-2026-71219: gfs2-utils stack overflow via di_depth
- CVE-2026-85089: FreeRDP server memory info leak
- CVE-2026-71222: gfs2-utils heap OOB read
- CVE-2026-71224: gfs2-utils stack exhaustion DoS
- CVE-2026-85049: Firefox Skia use-after-free RCE (CVSS 8.8)
- CVE-2026-84394: dotnet fast-uri host confusion SSRF bypass
- CVE-2026-85091: zlib gz_vacate heap buffer overflow
- CVE-2026-85150: GStreamer RTSP NULL deref DoS
- CVE-2026-85045: Node.js V8 race condition RCE
- CVE-2026-71221: gfs2-utils savemeta stack OOB write
- CVE-2026-85062: colord CSS colour parser ReDoS
- CVE-2026-84185: jwcrypto JWS signature verification flaw
- CVE-2026-76642: util-linux ignores mount helper failure
- CVE-2026-12704: pcp/Grafana SAML assertion replay
- CVE-2026-84837: rpm rpmbuild command injection
- CVE-2026-17516: qemu unspecified guest-to-host flaw (CVSS 8.8)
- CVE-2026-14199: pcp/Grafana Auth Proxy cache auth bypass
- CVE-2026-84347: Firefox WebRTC use-after-free RCE (CVSS 8.8)
- CVE-2026-81928: Net::DNS unbounded recursion DoS
- CVE-2026-78662: golang SSH channel flood DoS
- CVE-2026-78409: util-linux X-mount.subdir symlink escape
- CVE-2026-53683: FreeIPA password reset open redirect
- CVE-2026-84359: Firefox Skia cross-origin info leak
- CVE-2026-18329: nginx njs js_access auth bypass (CVSS 8.2)
- CVE-2026-56855: golang SSH connection deadlock DoS
- CVE-2026-84326: Node.js V8 uninitialised memory RCE (CVSS 8.8)
- CVE-2026-19475: pcp/Grafana SQL macro injection DoS
- CVE-2026-78689: nginx njs XML parser heap OOB write (CVSS 8.2)
- CVE-2026-78410: util-linux bind mount source swap privesc
- CVE-2026-78408: util-linux nsenter cgroup fd privesc
- CVE-2026-78222: nginx njs worker crash on bad response
- CVE-2026-84838: rpm rpmuncompress command injection
- CVE-2026-82522: libjxl integer underflow metadata injection
- CVE-2026-16658: Ansible proxmox_pct_remote command injection
- CVE-2026-82968: Keycloak identity provider link takeover
- CVE-2026-84121: Firefox DOM use-after-free sandbox escape
- CVE-2026-84136: Firefox DOM navigation issue
- CVE-2026-84145: Firefox memory safety bugs (CVSS 8.8)
- CVE-2026-63321: qemu unspecified device emulation flaw
- CVE-2026-63323: qemu unspecified device emulation flaw
- CVE-2026-63320: qemu unspecified device emulation flaw
- CVE-2026-84129: Firefox site isolation bypass
- CVE-2026-59944: Composer bin path traversal
- CVE-2026-84140: Firefox site isolation bypass
- CVE-2026-16288: qemu unspecified device emulation DoS
- CVE-2026-84270: gvfs MTP backend heap OOB read
- CVE-2026-84641: Thunderbird IMAP use-after-free and info leak
- CVE-2026-61476: qemu unspecified device emulation flaw
- CVE-2026-84304: gRPC-Go HTTP/2 memory exhaustion DoS
- CVE-2026-84132: Firefox HTTP networking info leak
- CVE-2026-84119: Firefox DOM use-after-free sandbox escape
- CVE-2026-84637: Thunderbird calendar invite runs executables
- CVE-2026-65928: qemu unspecified device emulation flaw
- CVE-2026-84128: Firefox WebDriver BiDi privesc
- CVE-2026-84267: gvfs SFTP backend info leak
- CVE-2026-18743: popt memory corruption via crafted config
- CVE-2026-84303: gRPC-Go xDS RBAC header matching auth bypass
- CVE-2026-84142: Firefox memory safety bugs
- CVE-2026-61406: qemu unspecified device emulation flaw
- CVE-2026-19032: jackson-databind Path deserialization flaw
- CVE-2026-84126: Firefox Layout Grid OOB write (CVSS 8.8)
- CVE-2026-63322: qemu unspecified device emulation flaw
- CVE-2026-61405: qemu unspecified device emulation flaw
- CVE-2026-63109: qemu unspecified device emulation DoS
- CVE-2026-61402: qemu unspecified device emulation flaw
- CVE-2026-84268: gvfs SFTP backend heap overflow (CVSS 8.8)
- CVE-2026-84118: Firefox JavaScript GC use-after-free (CVSS 8.8)
- CVE-2026-84144: Firefox memory safety bugs (CVSS 8.8)
- CVE-2026-84640: Thunderbird mail header OOB read
- CVE-2026-84639: Thunderbird MIME uninitialised memory use
- CVE-2026-84133: Firefox site isolation bypass
- CVE-2026-58582: qemu unspecified device emulation flaw
- CVE-2026-61404: qemu unspecified device emulation flaw
- CVE-2026-84127: Firefox for Android WebExtensions info leak
- CVE-2026-84122: Firefox Audio/Video use-after-free (CVSS 8.8)
- CVE-2026-84361: Composer Perforce URL command execution
- CVE-2026-84137: Firefox DOM spoofing issue
- CVE-2026-84143: Firefox memory safety bugs (CVSS 8.8)
- CVE-2026-63110: qemu unspecified device emulation DoS
- CVE-2026-84134: Firefox profile backup issue
- CVE-2026-84125: Firefox DOM use-after-free (CVSS 8.8)
- CVE-2026-84305: sqlparse quadratic reindent CPU DoS
- CVE-2026-84120: Firefox Audio/Video use-after-free (CVSS 8.8)
- CVE-2026-50624: qemu unspecified device emulation flaw
- CVE-2026-84131: Firefox Graphics invalid pointer privesc (CVSS 8.2)
- CVE-2026-84141: Firefox ImageLib integer overflow
- CVE-2026-65929: qemu unspecified device emulation flaw
- CVE-2026-84123: Firefox WebGPU use-after-free privesc (CVSS 8.8)
- CVE-2026-84139: Firefox DOM events clickjacking
- CVE-2026-84135: Firefox Focus for Android issue
- CVE-2026-84117: Firefox for Android privesc
- CVE-2026-66022: qemu unspecified device emulation flaw
- CVE-2026-11873: FreeIPA Dogtag CA log amplification DoS
- CVE-2026-84642: Thunderbird attachment hostname regex flaw
- CVE-2026-84138: Firefox PDF viewer DoS
- CVE-2026-15264: qemu unspecified guest-to-host flaw (CVSS 8.8)
- CVE-2026-84130: Firefox WebGPU info leak
- CVE-2026-18054: qemu unspecified device emulation DoS
- CVE-2026-58581: qemu unspecified device emulation DoS
- CVE-2026-53682: Dogtag PKI unauthenticated topology info leak
- CVE-2026-84124: Firefox DOM use-after-free (CVSS 8.8)
- CVE-2026-84269: gvfs AFP backend heap OOB read
- CVE-2026-83557: jackson-databind polymorphic type bypass
- CVE-2026-84233: rpm rpmuncompress macro command injection
๐บ AWS security bulletins
- CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
- CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
- CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
- CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
- CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
- CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
- CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
- CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
- CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
๐ฌ Security documentation changes
No changes this week.