Monday, April 20, 2026
City and Coffee
  • Home
  • World
    What’s behind the US army’s decision to raise enlistment age to 42? | Military News

    What’s behind the US army’s decision to raise enlistment age to 42? | Military News

    Russia confirms high-level talks on Ukraine in Saudi Arabia | News

    Trump says US negotiators to head to Pakistan for Iran ceasefire talks | News

    North Korea launches ballistic missiles towards sea off its east coast | Kim Jong Un News

    North Korea launches ballistic missiles towards sea off its east coast | Kim Jong Un News

    Iran’s deputy FM says no date for more US talks until ‘framework’ agreed | US-Israel war on Iran News

    Iran’s deputy FM says no date for more US talks until ‘framework’ agreed | US-Israel war on Iran News

    UN aid chief warns of possible ‘full-scale famine’ in South Sudan | United Nations

    UN aid chief warns of possible ‘full-scale famine’ in South Sudan | United Nations

  • US

    8 Children Killed in Domestic Mass Shooting in Shreveport, Louisiana, Police Say

    Syrian Billionaires Needed a Favor in Washington. They Invoked the Trump Name.

    U.S. Installs a Trump Loyalist to Lead ‘Grand Conspiracy’ Case Into Trump Foes

    Inside the Supreme Court’s Risky New Way of Doing Business

    Trump’s Dispute With Pope Leo Deepens Divisions on the Right

  • Europe
    Rumen Radev looks set to win Bulgarian Parliamentary election

    Rumen Radev looks set to win Bulgarian Parliamentary election

    Rat poison found in HiPP baby food jar in Austria, police say

    Rat poison found in HiPP baby food jar in Austria, police say

    Mexico's Sheinbaum denies 'diplomatic crisis' with Spain after conquest row

    Mexico's Sheinbaum denies 'diplomatic crisis' with Spain after conquest row

    Palestinians hand over suspect in 1982 attack on Jewish restaurant in Paris

    Palestinians hand over suspect in 1982 attack on Jewish restaurant in Paris

    UK seeks closer EU ties in volatile times – but at what cost?

    UK seeks closer EU ties in volatile times – but at what cost?

  • MENA
    US releases video of forces seizing Iranian ship

    US releases video of forces seizing Iranian ship

    US intercepts and seizes Iranian-flagged cargo ship, Trump says

    US intercepts and seizes Iranian-flagged cargo ship, Trump says

    French peacekeeper killed in southern Lebanon

    French peacekeeper killed in southern Lebanon

    Strait of Hormuz closed again, Iran says, as ships attacked

    Strait of Hormuz closed again, Iran says, as ships attacked

    Fuel truck leaves trail of fire on road in Syria

    Fuel truck leaves trail of fire on road in Syria

  • APAC
    New Zealand declares state of emergency in Wellington as floods hit

    New Zealand declares state of emergency in Wellington as floods hit

    Drone footage shows huge Malaysian coastal village fire

    Drone footage shows huge Malaysian coastal village fire

    The South Korean authors rising above a tide of hate to become bestsellers

    The South Korean authors rising above a tide of hate to become bestsellers

    One dead after car hits pedestrians in Melbourne, police say

    One dead after car hits pedestrians in Melbourne, police say

    Chinese carmaker patents voice-controlled 'in-vehicle toilet'

    Chinese carmaker patents voice-controlled 'in-vehicle toilet'

  • Tech
    The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad

    The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad

    Best Meta Glasses (2026): Ray-Ban, Oakley, AR

    Best Meta Glasses (2026): Ray-Ban, Oakley, AR

    Our Favorite Apple Watch Has Never Been Less Expensive

    Our Favorite Apple Watch Has Never Been Less Expensive

    The Best Smart Home Accessories to Boost Your Curb Appeal (2026)

    The Best Smart Home Accessories to Boost Your Curb Appeal (2026)

    The Best Movies to Stream This Month (April 2026)

    The Best Movies to Stream This Month (April 2026)

  • Entertainment
    ‘Days of Our Lives,’ ‘Melrose Place’ Actor Was 57

    ‘Days of Our Lives,’ ‘Melrose Place’ Actor Was 57

    Ella Langley’s ‘Dandelion’ Debuts at No. 1 on Billboard Album Chart

    Ella Langley’s ‘Dandelion’ Debuts at No. 1 on Billboard Album Chart

    Justin Bieber Serenades Billie Eilish, Duets With SZA at Coachella

    Justin Bieber Serenades Billie Eilish, Duets With SZA at Coachella

    Madonna Joins Sabrina Carpenter at Coachella for ‘Vogue,’ New Duet

    Madonna Joins Sabrina Carpenter at Coachella for ‘Vogue,’ New Duet

    Taraji P. Henson Says Hollywood Franchise Movies Won’t Cast Her

    Taraji P. Henson Says Hollywood Franchise Movies Won’t Cast Her

  • Travel
    This Seaside Town Is a Hidden Gem in California

    This Seaside Town Is a Hidden Gem in California

    Wimberley, Texas, Travel Guide

    Wimberley, Texas, Travel Guide

    15 Best Places to Visit in Georgia

    15 Best Places to Visit in Georgia

    Essential Guide to Beaufort, South Carolina

    Essential Guide to Beaufort, South Carolina

    REI Has Spring New Arrivals on Sale From $13

    REI Has Spring New Arrivals on Sale From $13

  • Lifestyle
    60 Thoughts I Had About Season 3, Episode 2 of ‘Euphoria’

    60 Thoughts I Had About Season 3, Episode 2 of ‘Euphoria’

    Zendaya Delivers One More Cheeky Bridal Serve for Her ‘The Drama’ Tour

    Zendaya Delivers One More Cheeky Bridal Serve for Her ‘The Drama’ Tour

    Dior Fashioned Ethel Cain a “Haunted” Dress for Coachella

    Dior Fashioned Ethel Cain a “Haunted” Dress for Coachella

    The Best Celebrity Coachella Outfits of 2026 So Far: Katseye, Ethel Cain & More

    The Best Celebrity Coachella Outfits of 2026 So Far: Katseye, Ethel Cain & More

    Dream Baby Press’s First London Reading Served Erotica With a Side of Elvis Presley

    Dream Baby Press’s First London Reading Served Erotica With a Side of Elvis Presley

  • Sports
    2026 NBA playoffs: Western Conference first-round takeaways

    2026 NBA playoffs: Western Conference first-round takeaways

    Dexter Lawrence trade: Bengals, Giants, NFL draft takeaways

    Dexter Lawrence trade: Bengals, Giants, NFL draft takeaways

    2026 NFL draft: Louis Riddick’s favorite prospects, sleepers

    2026 NFL draft: Louis Riddick’s favorite prospects, sleepers

    NBA offseason: Draft, free agency, trade targets for eliminated teams

    NBA offseason: Draft, free agency, trade targets for eliminated teams

    Sue Bird, Megan Rapinoe announce separation on social media

    Sue Bird, Megan Rapinoe announce separation on social media

  • Blogs
No Result
View All Result
City and Coffee
No Result
View All Result
Home Tech

An AWS Configuration Issue Could Expose Thousands of Web Apps

content@helloomylife.com by content@helloomylife.com
August 20, 2024
in Tech
0
An AWS Configuration Issue Could Expose Thousands of Web Apps
0
SHARES
63
VIEWS
Share on FacebookShare on Twitter


A vulnerability associated to Amazon Net Service’s traffic-routing service generally known as Utility Load Balancer may have been exploited by an attacker to bypass entry controls and compromise internet purposes, in accordance with new analysis. The flaw stems from a buyer implementation concern, which means it is not brought on by a software program bug. As an alternative, the publicity was launched by the way in which AWS customers arrange authentication with Utility Load Balancer.

Implementation points are a vital part of cloud safety in the identical means that the contents of an armored protected aren’t protected if the door is left ajar. Researchers from the safety agency Miggo found that, relying on how Utility Load Balancer authentication was arrange, an attacker may doubtlessly manipulate its handoff to a third-party company authentication service to entry the goal internet software and examine or exfiltrate knowledge.

The researchers say that publicly reachable internet purposes, they’ve recognized greater than 15,000 that seem to have susceptible configurations. AWS disputes this estimate, although, and says that “a small fraction of a p.c of AWS prospects have purposes doubtlessly misconfigured on this means, considerably fewer than the researchers’ estimate.” The corporate additionally says that it has contacted every buyer on its shorter checklist to suggest a safer implementation. AWS doesn’t have entry or visibility into its purchasers’ cloud environments, although, so any actual quantity is simply an estimate.

The Miggo researchers say they got here throughout the issue whereas working with a shopper. This “was found in real-life manufacturing environments,” Miggo CEO Daniel Shechter says. “We noticed a bizarre habits in a buyer system—the validation course of appeared prefer it was solely being executed partially, like there was one thing lacking. This actually reveals how deep the interdependencies go between the shopper and the seller.”

To use the implementation concern, an attacker would arrange an AWS account and an Utility Load Balancer, after which signal their very own authentication token as regular. Subsequent, the attacker would make configuration modifications so it will seem their goal’s authentication service issued the token. Then the attacker would have AWS signal the token as if it had legitimately originated from the goal’s system and use it to entry the goal software. The assault should particularly goal a misconfigured software that’s publicly accessible or that the attacker already has entry to, however would permit them to escalate their privileges within the system.

Amazon Net Providers says that the corporate doesn’t view token forging as a vulnerability in Utility Load Balancer as a result of it’s primarily an anticipated end result of selecting to configure authentication in a selected means. However after the Miggo researchers first disclosed their findings to AWS originally of April, the corporate made two documentation changes geared at updating their implementation suggestions for Utility Load Balancer authentication. One, from Might 1, included steering to add validation earlier than Utility Load Balancer will signal tokens. And on July 19, the corporate additionally added an express suggestion that customers set their techniques to obtain visitors from solely their very own Utility Load Balancer using a feature called “security groups.”



Source link

Tags: AppsAWSConfigurationExposeIssueThousandsWeb
Previous Post

Taylor Swift Debuts ‘I Can Do It With A Broken Heart’ Music Video

Next Post

Everest’s Sherpas fear their homeland is at risk of washing away

Next Post
Everest’s Sherpas fear their homeland is at risk of washing away

Everest's Sherpas fear their homeland is at risk of washing away

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Premium Content

Brown University shooting: What we know so far | Gun Violence News

Brown University shooting: What we know so far | Gun Violence News

December 14, 2025
Spain and Portugal reel from the impact of Storm Leonardo

Spain and Portugal reel from the impact of Storm Leonardo

February 7, 2026
WIRED Roundup: The US Chip Manufacturers’ Bonanza

WIRED Roundup: The US Chip Manufacturers’ Bonanza

August 26, 2025

Browse by Category

  • APAC
  • Entertainment
  • Europe
  • Lifestyle
  • MENA
  • Sports
  • Tech
  • Travel
  • US
  • World

Browse by Tags

Amazon attack attacks ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week World Years
City and Coffee

We provide the most reliable and up-to-date news from around the globe. Stay informed with our unbiased coverage of the latest events, trends, and stories. Trust us as your daily source for breaking news and insightful analysis

Browse by Tag

Amazon attack attacks ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week World Years

Recent Posts

  • US releases video of forces seizing Iranian ship
  • New Zealand declares state of emergency in Wellington as floods hit
  • The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad
  • ‘Days of Our Lives,’ ‘Melrose Place’ Actor Was 57
No Result
View All Result
  • Home
  • World
  • US
  • Europe
  • MENA
  • APAC
  • Tech
  • Entertainment
  • Travel
  • Lifestyle
  • Sports
  • Blogs

© 2024 All Rights Reserved | cityandcoffee.com

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?