An AWS Configuration Issue Could Expose Thousands of Web Apps

Amazon News

An AWS Configuration Issue Could Expose Thousands of Web Apps
Cloud ComputingSecurityCybersecurity
  • 📰 WIRED
  • ⏱ Reading Time:
  • 19 sec. here
  • 7 min. at publisher
  • 📊 Quality Score:
  • News: 28%
  • Publisher: 51%

Amazon has updated its instructions for how customers should more securely implement AWS's traffic-routing service known as Application Load Balancer, but it's not clear everyone will get the memo.

A vulnerability related to Amazon Web Service's traffic-routing service known as Application Load Balancer could have been exploited by an attacker to bypass access controls and compromise web applications, according to new research. The flaw stems from a customer implementation issue, meaning it isn't caused by a software bug. Instead, the exposure was introduced by the way AWS users set up authentication with Application Load Balancer.

Then the attacker would have AWS sign the token as if it had legitimately originated from the target's system and use it to access the target application. The attack must specifically target a misconfigured application that is publicly accessible or that the attacker already has access to, but would allow them to escalate their privileges in the system.

We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

WIRED /  🏆 555. in US

Cloud Computing Security Cybersecurity Enterprise Hacks

United Kingdom Latest News, United Kingdom Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

Inflation expected to cool slightly in July report as issue becomes key issue in presidential campaignInflation expected to cool slightly in July report as issue becomes key issue in presidential campaignThe July consumer price index report is expected to show that inflation cooled slightly to 2.9% year-over-year, while the Fed eyes rate cuts and inflation becomes a key election issue.
Read more »

Alaska Airlines seat configuration updates preparing to take flightAlaska Airlines seat configuration updates preparing to take flightThe changes will augment premium and first-class seating in its mainline fleet, with the expansion increasing annual premium seats by 1.3 million. Alaska Airlines said the updates respond to what they call a structural shift toward higher demand for premium products.
Read more »

Ram still considering a three-row configuration for pickup | Car NewsRam still considering a three-row configuration for pickup | Car NewsRam has submitted patent applications for innovations introduced with the 1500 Revolution BEV concept pickup, including a third row. Auto123 has more.
Read more »

Notre Dame Still Struggling To Find Winning Offensive Line Combination?Notre Dame Still Struggling To Find Winning Offensive Line Combination?The instability on the offensive line shows the lack of comfort with the current configuration.
Read more »

GE HealthCare taps Amazon Web Services to build generative AI for medical useGE HealthCare taps Amazon Web Services to build generative AI for medical useGE HealthCare and AWS team up to build generative AI applications for medical use
Read more »

Microsoft And AWS Outages: A Wake-Up Call For Cloud DependencyMicrosoft And AWS Outages: A Wake-Up Call For Cloud DependencyEmil Sayegh is a serial Tech CEO with over 12 years of experience as a Private Equity backed CEO and more than 25 years in the IT and tech industry.
Read more »



Render Time: 2025-03-31 19:16:30