<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Toc Consulting - Weekly AWS Security News</title>
    <link>https://tocconsulting.fr/weekly-news</link>
    <description>Weekly AWS security digest: CVEs, service updates, breach analysis, and threat intelligence. Curated by Toc Consulting for cloud security professionals.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 24 May 2026 12:00:00 GMT</lastBuildDate>
    <atom:link href="https://tocconsulting.fr/weekly-news/rss.xml" rel="self" type="application/rss+xml" />
    <generator>scripts/generate-rss.mjs</generator>
    <image>
      <url>https://tocconsulting.fr/logos/og-image.png</url>
      <title>Toc Consulting - Weekly AWS Security News</title>
      <link>https://tocconsulting.fr/weekly-news</link>
    </image>
    <item>
      <title>Security Hub Hunts Down Unused Access</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W21</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W21</guid>
      <pubDate>Sun, 24 May 2026 12:00:00 GMT</pubDate>
      <description>Security Hub learns to find identity risk that no one is using: unused IAM permissions, roles, and credentials, measured against 90 days of real activity. The Extended plan grows to 21 partners across 9 categories. Secrets Manager Agent picks up pre-fetching and cross-account role assumption, and Amazon Inspector Classic reaches end of support.</description>
    </item>
    <item>
      <title>DirtyFrag Hits Half of AWS</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W20</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W20</guid>
      <pubDate>Sun, 17 May 2026 12:00:00 GMT</pubDate>
      <description>AWS publishes bulletin 2026-030-AWS, a single rolling document for the Copy.fail / DirtyFrag Linux kernel privilege-escalation class. If you run Amazon Linux, Bottlerocket, ECS, EKS, EMR, Fargate, or SageMaker, this is the bulletin you bookmark. Security Agent meanwhile learns to read whole repositories.</description>
    </item>
    <item>
      <title>The DirtyFrag Bulletin Begins</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W19</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W19</guid>
      <pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
      <description>AWS opens what will become the defining CVE story of May: a Linux kernel privilege escalation tracked across half a dozen services. JDBC Wrapper ships column-level client-side encryption via KMS. AgentCore previews agent-to-agent payments via Coinbase and Stripe. AWS MCP Server reaches GA. WorkSpaces for AI Agents enters preview.</description>
    </item>
    <item>
      <title>Five FreeRTOS CVEs, One ECS RCE, One WorkSpaces LPE</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W18</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W18</guid>
      <pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate>
      <description>Heavy patch week if you ship IoT on FreeRTOS or run Windows containers: five FreeRTOS CVEs across three bulletins, an ECS Agent command injection to SYSTEM, a WorkSpaces local-privilege escalation. AWS CIRT publishes the March 2026 attacker-technique catalog with three notable new entries. Audit Manager officially closes to new customers. The What&apos;s Next with AWS 2026 event lands with the OpenAI partnership.</description>
    </item>
    <item>
      <title>AWS Picks a Fight with Quantum Decryption</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W17</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W17</guid>
      <pubDate>Mon, 27 Apr 2026 12:00:00 GMT</pubDate>
      <description>Secrets Manager rolls out hybrid post-quantum TLS using ML-KEM, baked into the agent, the Lambda extension, and the CSI driver. Three CVE bulletins land in the same week (QnABot, Ops Wheel, tough/tuftool). AWS finally gives the IAM Service Authorization Reference the deep-dive treatment.</description>
    </item>
    <item>
      <title>Vercel Got Pwned Through a Calendar App</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W16</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W16</guid>
      <pubDate>Mon, 20 Apr 2026 12:00:00 GMT</pubDate>
      <description>A Vercel employee had OAuth-trusted Context.ai with their corporate Google account. Lumma Stealer hit Context.ai. The attacker walked from Google Workspace into Vercel and read non-sensitive environment variables. Also this week: Vect ransomware lists Trivy/LiteLLM victims, AWS patches EFS CSI and Encryption SDK for Python.</description>
    </item>
    <item>
      <title>Axios CVE Looks Bad on Paper, Works Mostly Nowhere</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W15</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W15</guid>
      <pubDate>Mon, 13 Apr 2026 12:00:00 GMT</pubDate>
      <description>A CVSS 9.9 in Axios chains prototype pollution into IMDSv2 credential theft. Node.js already blocks the technique at the runtime layer, so production Node apps are mostly safe. Browser apps and other runtimes are not. AWS also ships Project Glasswing with Anthropic and patches a Firecracker virtio-pci out-of-bounds write.</description>
    </item>
    <item>
      <title>Two AWS Agents Reach GA the Same Day</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W14</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W14</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>Security Agent and DevOps Agent both ship to general availability after their re:Invent 2025 preview. S3 finally rolls out the SSE-C default-off across 37 Regions, the kill announced back in January. Audit Manager stops onboarding new customers as of April 30.</description>
    </item>
    <item>
      <title>The European Commission Lost Its AWS Account</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W13</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W13</guid>
      <pubDate>Mon, 30 Mar 2026 12:00:00 GMT</pubDate>
      <description>Over 350 GB stolen from the European Commission&apos;s AWS environment, confirmed publicly March 27. AWS clarifies its services were not breached, this is shared-responsibility 101 played out at the highest level of EU government. LiteLLM packages get backdoored to steal IMDS credentials. RSAC 2026 happens in San Francisco.</description>
    </item>
    <item>
      <title>Four CVEs, One Cisco Zero-Day, One Trivy Compromise</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W12</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W12</guid>
      <pubDate>Sun, 22 Mar 2026 12:00:00 GMT</pubDate>
      <description>AWS issues four security bulletins in a single week, signaling fresh scrutiny on developer tooling and cryptographic libraries. Trivy CI/CD pipelines get backdoored by TeamPCP. Amazon publishes 36-day-old honeypot intel on Interlock ransomware exploiting Cisco Firewall Management Center.</description>
    </item>
    <item>
      <title>Security Hub Goes Multicloud, Sovereign Cloud Gets SOC 2</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W11</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W11</guid>
      <pubDate>Sun, 15 Mar 2026 12:00:00 GMT</pubDate>
      <description>Security Hub Extended officially expands to AWS, Azure, GCP, OCI, and Kubernetes, the long-anticipated cross-cloud play. European Sovereign Cloud completes SOC 2 Type 2 and BSI C5 audits. IAM Roles Anywhere ships post-quantum signing via ML-DSA. Inspector Classic gets a May 2026 EOL date.</description>
    </item>
    <item>
      <title>AgentCore Picks Up Cedar Policies</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W10</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W10</guid>
      <pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
      <description>Bedrock AgentCore Policy hits GA, mixing LLM authorship with Cedar policy-as-code, the first AWS service to do that at scale. IAM gets a simplified role-creation flow with inline panels. AWS adds DESC 2026 certification for the UAE.</description>
    </item>
    <item>
      <title>The Heaviest Security Week of Q1</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W09</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W09</guid>
      <pubDate>Mon, 02 Mar 2026 12:00:00 GMT</pubDate>
      <description>Security Hub Extended Plan reaches GA with 14+ partners on day one, the launch most enterprises have been waiting for. LexisNexis loses 2 GB via a misconfigured AWS environment. Three AWS-LC crypto library CVEs land in one drop. VPC Encryption Controls move from preview to paid.</description>
    </item>
    <item>
      <title>600 FortiGate Boxes Compromised, 55 Countries</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W08</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W08</guid>
      <pubDate>Mon, 23 Feb 2026 12:00:00 GMT</pubDate>
      <description>Amazon publishes the full picture of the AI-augmented FortiGate campaign tracked since Week 5: 600+ devices compromised across 55 countries, with LLM-generated tooling automating reconnaissance through lateral movement. AWS development tools get the agent-plugin treatment. Kiro IDE expands to GovCloud.</description>
    </item>
    <item>
      <title>Aurora Now Encrypts by Default</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W07</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W07</guid>
      <pubDate>Mon, 16 Feb 2026 12:00:00 GMT</pubDate>
      <description>New Aurora clusters get encryption at rest with zero opt-in, closing a gap that has caused too many &quot;we forgot to enable encryption&quot; audit findings. AWS Backup adds PrivateLink for SAP HANA workloads. Elastic Beanstalk patches a Windows Server vulnerability.</description>
    </item>
    <item>
      <title>Security Groups Finally Tell You What Uses Them</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W06</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W06</guid>
      <pubDate>Mon, 09 Feb 2026 12:00:00 GMT</pubDate>
      <description>Security Groups finally show a &quot;Related Resources&quot; tab listing every dependent resource, a quality-of-life win years overdue. Security Agent now scopes shared VPCs. Claude Opus 4.6 lands in Amazon Bedrock.</description>
    </item>
    <item>
      <title>The FortiGate Campaign Starts Buzzing</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W05</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W05</guid>
      <pubDate>Mon, 02 Feb 2026 12:00:00 GMT</pubDate>
      <description>Amazon Threat Intelligence begins tracking an AI-augmented campaign compromising FortiGate enterprise firewalls at scale. STS OIDC federation enhancements ship. SageMaker quietly tightens its public endpoint defaults.</description>
    </item>
    <item>
      <title>Security Agent Reads Your GitHub</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W04</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W04</guid>
      <pubDate>Mon, 26 Jan 2026 12:00:00 GMT</pubDate>
      <description>Security Agent extends preview support to GitHub Enterprise Cloud, so your code, IaC, and supply chain now sit on the same scanning surface. Network Firewall picks up GenAI traffic classification. S3 lets you change a bucket&apos;s encryption type without re-uploading objects.</description>
    </item>
    <item>
      <title>The European Sovereign Cloud Goes Live</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W03</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W03</guid>
      <pubDate>Mon, 19 Jan 2026 12:00:00 GMT</pubDate>
      <description>AWS European Sovereign Cloud goes live in Brandenburg, run by EU residents under German law, physically and logically isolated from other Regions. The Sovereign Reference Framework establishes how it is governed.</description>
    </item>
    <item>
      <title>Kiro IDE Ships RCE in Its Welcome Mat</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W02</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W02</guid>
      <pubDate>Mon, 12 Jan 2026 12:00:00 GMT</pubDate>
      <description>A CVSS 8.4 command injection in AWS&apos;s new Kiro IDE lets a crafted project execute code the moment you open it. Client VPN gets simplified onboarding. AWS is named ISG Leader for Sovereign Cloud for the third year running.</description>
    </item>
    <item>
      <title>S3 SSE-C Encryption Gets the Boot</title>
      <link>https://tocconsulting.fr/weekly-news/2026-W01</link>
      <guid isPermaLink="true">https://tocconsulting.fr/weekly-news/2026-W01</guid>
      <pubDate>Mon, 05 Jan 2026 12:00:00 GMT</pubDate>
      <description>AWS announces SSE-C will be disabled by default on new general-purpose S3 buckets starting April 2026, closing the Codefinger ransomware vector. Security Hub and Security Agent updates from re:Invent 2025 keep rolling out.</description>
    </item>
  </channel>
</rss>
