Latest AWS Lambda image scan detected 28 CVEs across 26 images:
โข ๐ด Critical: 2
โข ๐ High: 8
โข ๐ก Medium: 14
โข ๐ต Low: 4
Check the full report ๐ https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless
๐จ AWS Language Server Flaw!
CVE-2026-12957 allows zero-click command injection and cloud credential theft simply by opening a poisoned repository inside your IDE (affecting Amazon Q Developer).
https://denizhalil.com/2026/06/27/cve-2026-12957-aws-language-server-command-injection/

Deep dive into CVE-2026-12957, a critical zero-click command injection flaw in Language Servers for AWS affecting Amazon Q Developer
Backup cloud sicuro per Linux con versioning, storage immutabile e ripristino rapido e molto altro ancora il tutto tramite IDrive. #LinuxBackup #IDrive #SysAdmin #CloudSecurity #DisasterRecovery #Software
๐ New here. AWS security engineer in Paris, AWS Community Builder.
I write open-source AWS security tooling: IAM privilege-escalation path detection, S3 / EC2 / Lambda misconfiguration scanners, and a tracker that records every change to AWS managed IAM policies over time.
Also maintain LocalEmu, a free local AWS emulator for testing without touching real accounts or credentials.
Here to learn from this community and share what I find. ๐
A PDF feature can be turned into a window into your servers.
php-weasyprint (1.2M+ installs) fetched attacker-controlled URLs server-side. Cloud metadata and local files were both in reach.
Run it? Upgrade to 2.6.0. (CVE-2026-49359)
Amazon AI Coding Tool Exposes Cloud Credentials to Malicious Git Repos
A security vulnerability in Amazon's AI coding assistant, tracked as CVE-2026-12957, allowed malicious Git repositories to access sensitive cloud credentials, raising concerns about informed consent and user security. The flaw enabled automatic execution of commands with no user prompt required.