Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
AWS
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain …

AWS
AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions

New AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a “project” where AWS and coding …

Amazon AWS
AWS puts AI vulnerability detection to the test, and false positives pile up

AWS’ Deception Benchmark measures how well AI models distinguish genuine security vulnerabilities from code that looks risky but is safe. AWS is making it publicly available …

AWS
AWS spent years rebuilding its routing control plane without taking the network down

Every AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt …

key
Your AI agent’s system prompt is not a security control

An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, VP …

DuckDB AWS
DuckDB stays open source while the team behind it goes to work for Amazon

Hannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to …

Amazon AWS
AWS Console Private Access can block sign-ins to personal accounts

The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private …

AWS
AWS makes it easier to spot firewall rules that have gone quiet

AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or …

AWS
AWS limits AI agents’ data access, even when manipulated

AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services …

AWS
AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, …

cloud
Weak IAM affects up to 98% of cloud environments

Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing …

AWS
AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools