Wednesday, February 18, 2026
City and Coffee
  • Home
  • World
    Video: War crimes complaint against Israeli sniper filed in Chile | Israel-Palestine conflict

    Video: War crimes complaint against Israeli sniper filed in Chile | Israel-Palestine conflict

    Tributes pour in after US civil rights icon Jesse Jackson dies at 84 | Obituaries News

    Tributes pour in after US civil rights icon Jesse Jackson dies at 84 | Obituaries News

    Video: Millions celebrate Lunar New Year ushering in the Year of the Horse | Newsfeed

    Video: Millions celebrate Lunar New Year ushering in the Year of the Horse | Newsfeed

    US Homeland Security Department’s funding negotiations stall | Politics News

    US Homeland Security Department’s funding negotiations stall | Politics News

    Which teams can qualify for the T20 World Cup Super Eights, and how? | ICC Men’s T20 World Cup News

    Which teams can qualify for the T20 World Cup Super Eights, and how? | ICC Men’s T20 World Cup News

  • US

    Nine Skiers Still Missing After Lake Tahoe Avalanche

    Jesse Jackson’s Hometown Remembers Him as a ‘Superstar’

    Jesse Jackson, Civil Rights Leader Who Sought the Presidency, Dies at 84

    2 Killed in Shooting at High School Hockey Game in Rhode Island

    ‘A Superstar Is From Here’: Pride of Cleveland Suburb Soars for U.S. Hockey

  • Europe
    Vinicius Junior says ‘racists are cowards’ as Gianluca Prestianni denies alleged abuse

    Vinicius Junior says ‘racists are cowards’ as Gianluca Prestianni denies alleged abuse

    Nine arrested in France over death of far-right student

    Nine arrested in France over death of far-right student

    Five young people die in Spain apartment block fire

    Five young people die in Spain apartment block fire

    Austrian man faces terror charges over Taylor Swift concert attack plot

    Austrian man faces terror charges over Taylor Swift concert attack plot

    Trump’s new world order is real and Europe is having to adjust fast

    Trump’s new world order is real and Europe is having to adjust fast

  • MENA
    I would scream in my sleep: Women from Syria's Alawite minority tell of kidnap and rape

    I would scream in my sleep: Women from Syria's Alawite minority tell of kidnap and rape

    US build-up of warships and fighter jets tracked near Iran

    US build-up of warships and fighter jets tracked near Iran

    Trump says he will be ‘indirectly’ involved in Iran nuclear talks

    Trump says he will be ‘indirectly’ involved in Iran nuclear talks

    Australian IS families in Syria camp turned back after leaving for home

    Australian IS families in Syria camp turned back after leaving for home

    Female Israeli soldiers rescued after being chased by ultra-Orthodox men

    Female Israeli soldiers rescued after being chased by ultra-Orthodox men

  • APAC
    Indian university faces backlash for claiming Chinese robodog as own at AI summit

    Indian university faces backlash for claiming Chinese robodog as own at AI summit

    Australia bans citizen trying to return from IS camp in Syria

    Australia bans citizen trying to return from IS camp in Syria

    Ex-NRL winger Matt Utai in serious condition after drive-by shooting

    Ex-NRL winger Matt Utai in serious condition after drive-by shooting

    China is piling pressure on Japan’s Sanae Takaichi. Will it work?

    China is piling pressure on Japan’s Sanae Takaichi. Will it work?

    ByteDance to curb AI video app after Disney legal threat

    ByteDance to curb AI video app after Disney legal threat

  • Tech
    This Defense Company Made AI Agents That Blow Things Up

    This Defense Company Made AI Agents That Blow Things Up

    Lovehoney Discount Codes and Deals: Up to 70% Off

    Lovehoney Discount Codes and Deals: Up to 70% Off

    The Curling Controversy at the Winter Olympics Isn’t What You Think

    The Curling Controversy at the Winter Olympics Isn’t What You Think

    The Small English Town Swept Up in the Global AI Arms Race

    The Small English Town Swept Up in the Global AI Arms Race

    Saatva Memory Foam Hybrid Mattress Review: Going for Gold and Good Sleep

    Saatva Memory Foam Hybrid Mattress Review: Going for Gold and Good Sleep

  • Entertainment
    Viola Davis Novel ‘Judge Stone’: Buy Online

    Viola Davis Novel ‘Judge Stone’: Buy Online

    Filmin Boards Funicular Films’ ‘Robbery, Beating and Death’

    Filmin Boards Funicular Films’ ‘Robbery, Beating and Death’

    CBS Denies Forcing Stephen Colbert to Not Air Talarico Interview Over FCC Rule

    CBS Denies Forcing Stephen Colbert to Not Air Talarico Interview Over FCC Rule

    Nippon TV Launches Viral Pocket Division to Expand Into Microdramas

    Nippon TV Launches Viral Pocket Division to Expand Into Microdramas

    Apple Podcasts Launching New Video Features

    Apple Podcasts Launching New Video Features

  • Travel
    7 of the Best Cruise Lines for Foodies, According to Travel Experts

    7 of the Best Cruise Lines for Foodies, According to Travel Experts

    How to Plan the Perfect Ski Trip to Sun Valley

    How to Plan the Perfect Ski Trip to Sun Valley

    The Essential Guide to Taipei, Taiwan

    The Essential Guide to Taipei, Taiwan

    Jackson Hole, Wyoming, Travel Guide

    Jackson Hole, Wyoming, Travel Guide

    This Lesser-visited National Park Is the Most Scenic in North America

    This Lesser-visited National Park Is the Most Scenic in North America

  • Lifestyle
    Kamiya Tokyo Fall 2026 Collection

    Kamiya Tokyo Fall 2026 Collection

    Rhude Fall 2026 Menswear Collection

    Rhude Fall 2026 Menswear Collection

    Staud Fall 2026 Ready-to-Wear Collection

    Staud Fall 2026 Ready-to-Wear Collection

    Bronx and Banco Fall 2026 Ready-to-Wear Collection

    Bronx and Banco Fall 2026 Ready-to-Wear Collection

    Bibhu Mohapatra Fall 2026 Ready-to-Wear Collection

    Bibhu Mohapatra Fall 2026 Ready-to-Wear Collection

  • Sports
    How the sports memorabilia industry tries to stay ahead of fraud

    How the sports memorabilia industry tries to stay ahead of fraud

    Men’s Bubble Watch: Tracking which teams will make (or miss) the NCAA tournament

    Men’s Bubble Watch: Tracking which teams will make (or miss) the NCAA tournament

    USA vs. Canada is the women’s Olympic hockey rematch everyone was waiting for

    USA vs. Canada is the women’s Olympic hockey rematch everyone was waiting for

    2026 Winter Olympics: Follow live updates Tuesday from Milan Cortina

    2026 Winter Olympics: Follow live updates Tuesday from Milan Cortina

    Follow live: USA, Sweden battle in semifinal for spot in gold medal match

    Follow live: USA, Sweden battle in semifinal for spot in gold medal match

  • Blogs
No Result
View All Result
City and Coffee
No Result
View All Result
Home Tech

An AWS Configuration Issue Could Expose Thousands of Web Apps

content@helloomylife.com by content@helloomylife.com
August 20, 2024
in Tech
0
An AWS Configuration Issue Could Expose Thousands of Web Apps
0
SHARES
61
VIEWS
Share on FacebookShare on Twitter


A vulnerability associated to Amazon Net Service’s traffic-routing service generally known as Utility Load Balancer may have been exploited by an attacker to bypass entry controls and compromise internet purposes, in accordance with new analysis. The flaw stems from a buyer implementation concern, which means it is not brought on by a software program bug. As an alternative, the publicity was launched by the way in which AWS customers arrange authentication with Utility Load Balancer.

Implementation points are a vital part of cloud safety in the identical means that the contents of an armored protected aren’t protected if the door is left ajar. Researchers from the safety agency Miggo found that, relying on how Utility Load Balancer authentication was arrange, an attacker may doubtlessly manipulate its handoff to a third-party company authentication service to entry the goal internet software and examine or exfiltrate knowledge.

The researchers say that publicly reachable internet purposes, they’ve recognized greater than 15,000 that seem to have susceptible configurations. AWS disputes this estimate, although, and says that “a small fraction of a p.c of AWS prospects have purposes doubtlessly misconfigured on this means, considerably fewer than the researchers’ estimate.” The corporate additionally says that it has contacted every buyer on its shorter checklist to suggest a safer implementation. AWS doesn’t have entry or visibility into its purchasers’ cloud environments, although, so any actual quantity is simply an estimate.

The Miggo researchers say they got here throughout the issue whereas working with a shopper. This “was found in real-life manufacturing environments,” Miggo CEO Daniel Shechter says. “We noticed a bizarre habits in a buyer system—the validation course of appeared prefer it was solely being executed partially, like there was one thing lacking. This actually reveals how deep the interdependencies go between the shopper and the seller.”

To use the implementation concern, an attacker would arrange an AWS account and an Utility Load Balancer, after which signal their very own authentication token as regular. Subsequent, the attacker would make configuration modifications so it will seem their goal’s authentication service issued the token. Then the attacker would have AWS signal the token as if it had legitimately originated from the goal’s system and use it to entry the goal software. The assault should particularly goal a misconfigured software that’s publicly accessible or that the attacker already has entry to, however would permit them to escalate their privileges within the system.

Amazon Net Providers says that the corporate doesn’t view token forging as a vulnerability in Utility Load Balancer as a result of it’s primarily an anticipated end result of selecting to configure authentication in a selected means. However after the Miggo researchers first disclosed their findings to AWS originally of April, the corporate made two documentation changes geared at updating their implementation suggestions for Utility Load Balancer authentication. One, from Might 1, included steering to add validation earlier than Utility Load Balancer will signal tokens. And on July 19, the corporate additionally added an express suggestion that customers set their techniques to obtain visitors from solely their very own Utility Load Balancer using a feature called “security groups.”



Source link

Tags: AppsAWSConfigurationExposeIssueThousandsWeb
Previous Post

Taylor Swift Debuts ‘I Can Do It With A Broken Heart’ Music Video

Next Post

Everest’s Sherpas fear their homeland is at risk of washing away

Next Post
Everest’s Sherpas fear their homeland is at risk of washing away

Everest's Sherpas fear their homeland is at risk of washing away

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Premium Content

Danish PM tells Trump to stop ‘threats’ against Greenland

Danish PM tells Trump to stop ‘threats’ against Greenland

January 4, 2026
Pope Leo XIV, First American Pontiff, Will Face a Fractured American Church

Pope Leo XIV, First American Pontiff, Will Face a Fractured American Church

May 9, 2025
12 Valentine’s Day Gifts for Solo Travelers 2026

12 Valentine’s Day Gifts for Solo Travelers 2026

February 14, 2026

Browse by Category

  • APAC
  • Entertainment
  • Europe
  • Lifestyle
  • MENA
  • Sports
  • Tech
  • Travel
  • US
  • World

Browse by Tags

Amazon attack ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Tested Top travel Trump Trumps U.S Ukraine war Week Win World Years
City and Coffee

We provide the most reliable and up-to-date news from around the globe. Stay informed with our unbiased coverage of the latest events, trends, and stories. Trust us as your daily source for breaking news and insightful analysis

Browse by Tag

Amazon attack ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Tested Top travel Trump Trumps U.S Ukraine war Week Win World Years

Recent Posts

  • Indian university faces backlash for claiming Chinese robodog as own at AI summit
  • This Defense Company Made AI Agents That Blow Things Up
  • Viola Davis Novel ‘Judge Stone’: Buy Online
  • 7 of the Best Cruise Lines for Foodies, According to Travel Experts
No Result
View All Result
  • Home
  • World
  • US
  • Europe
  • MENA
  • APAC
  • Tech
  • Entertainment
  • Travel
  • Lifestyle
  • Sports
  • Blogs

© 2024 All Rights Reserved | cityandcoffee.com

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?