Posts

Showing posts with the label AWS

European Commission sued for violating data protection laws it created

By Vilius Petkauskas,  Cyber News A German citizen is suing the European Commission for transferring citizens’ data from one of the Commission’s websites to the United States. In a twist of irony, the executive branch of the European Union (EU), the European Commission (EC), is being sued for violating the personal data protection laws it created. According to Europäische Gesellschaft für Datenschutz (EuGD), a Germany-based organization supporting consumers in the enforcement of legal claims over breaches of the General Data Protection Regulation (GDPR), a German consumer believes his right to the protection of personal data was violated. While the GDPR does not apply to European institutions directly, they have to follow a similar law that closely resembles the restrictive nature of the GDPR. Both sets of legislation were created with the help of the Commission. “When calling up the website […] and registering for an event offered there, the US cloud service in its function as web...

Massive Cloudflare outage caused by network configuration error

By Sergiu Gatlan,  Bleeping Computer Cloudflare says a massive outage that affected more than a dozen of its data centers and hundreds of major online platforms and services today was caused by a change that should have increased network resilience. "Today, June 21, 2022, Cloudflare suffered an outage that affected traffic in 19 of our data centers," Cloudflare said after investigating the incident. "Unfortunately, these 19 locations handle a significant proportion of our global traffic. This outage was caused by a change that was part of a long-running project to increase resilience in our busiest locations." According to user reports, the full list of affected websites and services includes, but it's not limited to, Amazon, Twitch, Amazon Web Services, Steam, Coinbase, Telegram, Discord, DoorDash, Gitlab, and more.

Thousands of GitHub, AWS, Docker tokens exposed in Travis CI logs

By Ionut Ilascu,  Bleeping Computer For a second time in less than a year, the Travis CI platform for software development and testing has exposed user data containing authentication tokens that could give access to developers’ accounts on GitHub , Amazon Web Services , and Docker Hub. Researchers at Aqua Security discovered that “tens of thousands of user tokens” are exposed through the Travis CI API that offer access to more than 770 million logs with various types of credentials belonging to free tier users.

Amazon Web Services fixes container escape in Log4Shell hotfix

Image
By Bill Toulas, Bleeping Computer Amazon Web Services (AWS) has fixed four security issues in its hot patch from December that addressed the critical Log4Shell vulnerability (CVE-2021-44228) affecting cloud or on-premise environments running Java applications with a vulnerable version of the Log4j logging library or containers. The hot patch packages from Amazon are not exclusive to AWS resources and allowed escaping a container in the environment and taking control of the host. The flaws could also be exploited through unprivileged processes to elevate privileges and execute code as with root permissions. The vulnerabilities are currently tracked as CVE-2021-3100, CVE-2021-3101, CVE-2022-0070, and CVE-2022-0071. All of them have been assessed as high-severity risks with a score of 8.8 out of 10. Hot patch trouble Security researchers at Palo Alto Network's Unit 42 discovered that Amazon's Log4Shell hot-fix solutions would keep searching for Java processes and patch them on the...