threat-intel CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing CISA conducted two red team assessments against two critical infrastructure organizations, revealing vastly different defensive capabilities. Organization A was completely compromised at the domain level, with no detection of the attack, due to a combination of poor security practices and a lack of effective monitoring… The Hacker News · 4d ago High red teamdomain compromisecredential theft
data-breach Electronic health record company CareCloud says 3.7 million people affected by breach CareCloud, a major electronic health record provider, experienced a data breach affecting 3.7 million people. Hackers gained unauthorized access to their AWS environment for eight hours, leading to the exposure of sensit… The Record · Aug 19, 2026 High data breachhealthcareaws
data-breach CareCloud Data Breach Impact Grows to 3.7 Million Individuals A significant data breach at CareCloud has impacted over 3.7 million individuals, exposing sensitive personal and medical information. The breach, initially detected in March, involved unauthorized access to CareCloud’s… SecurityWeek · Aug 19, 2026 High data breachhealthcareaws
threat-intel Xpander Raises $7.5 Million for AI Management and Governance Xpander, a startup founded by former AWS engineers, has secured $7.5 million in seed funding to help organizations manage and deploy AI agents. The platform aims to simplify AI adoption and governance for businesses stru… SecurityWeek · Aug 18, 2026 Info aiagentgovernance
data-breach Over 1,000 Charities Hit by Beacon CRM Data Breach A data breach at UK-based CRM provider Beacon has impacted over 1,000 charities, exposing supporter data including names, email addresses, and postal addresses. The breach stemmed from a compromised AWS access key and in… SecurityWeek · Aug 14, 2026 Medium GBdata breachcrmaws
data-breach CareCloud Data Breach Impacts Over 350,000 CareCloud, a healthcare IT company, experienced a data breach affecting over 350,000 individuals. Hackers gained access to an AWS environment, resulting in the theft of sensitive personal, financial, and medical informat… SecurityWeek · Jul 31, 2026 High data breachhealthcareaws
vulnerability Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS… The Hacker News · Jul 16, 2026 Critical awsiotcertificate
threat-intel Lessons Learned from CISA’s Recent GitHub Leak A CISA contractor inadvertently published a massive trove of sensitive credentials, including AWS GovCloud keys and plaintext passwords, in a public GitHub repository for nearly six months before CISA was notified. The a… Krebs on Security · Jul 13, 2026 High secretsgithubaws
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud
threat-intel Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility This article from Palo Alto Unit 42 details how attackers are exploiting cloud logging services, specifically AWS CloudTrail and Google Cloud Logging, to evade detection and gain continuous visibility into target environ… Palo Alto Unit 42 · Jun 9, 2026 High cloud securityloggingevasion
threat-intel FBI-Flagged Phishing Kit Kali365 Expands Its Reach The Kali365 phishing-as-a-service platform, initially focused on compromising Microsoft 365 accounts via MFA bypass, has significantly expanded its capabilities and target list. It now actively targets platforms like AWS… Dark Reading · Jun 2, 2026 High USRUphishingdevice-codemfa
threat-intel Lawmakers Demand Answers as CISA Tries to Contain Data Leak A significant security breach occurred involving the intentional publication of sensitive CISA data, including AWS GovCloud keys and internal system credentials, by a CISA contractor. The exposed data, hosted on a public… Krebs on Security · May 22, 2026 High USgithubcredentialleak
data-breach CISA Security Leak A contractor for CISA inadvertently exposed sensitive credentials and internal system details through a public GitHub repository. This included access to highly privileged AWS GovCloud accounts and information about CISA… Schneier on Security · May 22, 2026 Critical USgithubawscredentials
threat-intel CISA Exposes Secrets, Credentials in 'Private' Repo A public GitHub repository belonging to the Cybersecurity and Infrastructure Security Agency (CISA) was discovered containing 844MB of sensitive data, including plain-text passwords, authentication tokens, and cloud infr… Dark Reading · May 19, 2026 High USsecretsgithubcloud
threat-intel CISA Admin Leaked AWS GovCloud Keys on Github A contractor for CISA inadvertently exposed highly privileged AWS GovCloud credentials and internal CISA system information via a public GitHub repository. The repository contained plaintext passwords, cloud keys, and lo… Krebs on Security · May 18, 2026 High USgithubawscredentials
phishing “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security This Securelist article details a concerning trend of attackers leveraging Amazon Simple Email Service (Amazon SES) for phishing campaigns. Attackers exploit legitimate access keys to send convincing emails that bypass s… Securelist · May 4, 2026 High USphishingawsamazon ses