The ShinyHunters extortion group told BleepingComputer it exploited a new remote-code-execution flaw in Oracle PeopleSoft to access FBI systems and move into FBI-managed AWS GovCloud infrastructure, claiming theft of 2-3TB of data including employee, applicant, HR and Medlink records. The group shared a screenshot showing the FBI Jobs site defaced with its logo and a message asserting sensitive PII/PHI had been stolen, and said the FBI quickly took the affected systems offline.
bleepingcomputer.com
· 2026-09-22
Amazon Web Services is giving select customers early access to a video-generation AI model built by The Biological Computing Company, which derives its algorithms from patterns observed in rat brain cells. The startup records how biological neural tissue processes visual information and then designs software that mimics those processes, aiming to make existing generative video models more efficient. Both companies expect a broader rollout to AWS enterprise customers to follow this limited preview.
wired.com
· 2026-09-22
A Google Threat Intelligence Group analyst named Larsen ran a covert operation to observe the hacker collective TeamPCP, gaining access to a server where the group stored stolen credentials from numerous victim companies. Google used this visibility to rapidly notify cloud providers like AWS and Microsoft to revoke compromised access tokens before the hackers could exploit them for extortion, rather than trying to contact each victim individually.
arstechnica.com
· 2026-09-20
Amazon has acknowledged that its Bahrain AWS Region (me-south-1) suffered irreversible damage from Iranian missile and drone strikes during the US-Iran conflict, rendering hosted data and resources permanently inaccessible. The company also reported ongoing operational issues at its UAE region, where one availability zone was destroyed and two others are still being assessed for recovery.
techspot.com
· 2026-09-17
Snap is teaming up with Nvidia, Amazon Web Services and Salesforce to market its $2,195 Specs augmented reality glasses to businesses, aiming to position the device as a computing platform rather than a consumer camera accessory. CEO Evan Spiegel said the glasses could help field technicians view digital repair instructions and interact with coworkers, leveraging Nvidia's open-source XR AI platform. Snap also unveiled Specs Intelligence, an AI assistant working across the glasses, iPhones and Macs, with pricing still undetermined.
cnbc.com
· 2026-09-16
Ahead of their public offerings, Amazon in 1997 and Uber in 2019 each explicitly told investors in their IPO prospectuses that they might never turn a profit. Amazon debuted at $18 a share, raising about $54 million at a roughly $438 million valuation, while Uber priced at $45 a share in one of history's largest tech IPOs, valued above $82 billion.
techspot.com
· 2026-09-16
Amazon Web Services has told customers to relocate their data away from its Abu Dhabi and Bahrain facilities, more than six months after drone and missile strikes damaged both sites during regional conflict involving Iran, the US and Israel. AWS gave no timeline for repairs, and Bahraini state media reported that site was destroyed by cruise missiles.
tomshardware.com
· 2026-09-16
Amazon Web Services announced it cannot restore cloud infrastructure in Bahrain and part of the UAE, more than six months after drone strikes tied to the Iran war damaged the sites. AWS said the destruction exceeded what its systems were built to endure, permanently losing data and resources hosted exclusively there, while it continues trying to recover two other affected UAE zones.
cnbc.com
· 2026-09-15
F5's honeypots detected a month-long scanning campaign exploiting CVE-2026-39364, a high-severity flaw in Vite versions 7.1.0-7.3.2 and pre-8.0.5, that lets unauthenticated attackers bypass access controls via crafted query parameters like ?raw or ?import&raw. Over 800 attacks and roughly 32,000 events were recorded, with attackers hunting for environment files, AWS and Azure credentials, Terraform state files, and system files like /etc/passwd. Most activity came from the US, Belgium, and the Netherlands, with some attackers routing through Google Cloud IPs and also exploiting older Vite access-control bugs.
bleepingcomputer.com
· 2026-09-14
A volunteer running an NTP pool server discovered persistent attack traffic, including Log4Shell-style payloads, arriving from AWS-hosted IPs tied to the security firm Assetnote. The traffic carried Host headers referencing pool-ntp.tesla.com, a domain Tesla points via CNAME to the public NTP Pool, causing Assetnote's scanners to treat the volunteer's server as a Tesla-owned asset. The issue was reported and resolved after Assetnote's team responded.
dreamstation.systems
· 2026-09-13
A developer describes building two lightweight 'modes' inside Spotify's Portal platform to offload routine, low-reasoning coding tasks—like reading multiple files or generating repetitive test files—from Claude Code to a cheaper model, Gemini 2.5 Flash. The setup required no infrastructure, API keys, or new subscriptions, just declarative agent configurations run on Portal's serverless-style runtime, and reportedly slashed token usage by 90%.
engineering.atspotify.com
· 2026-09-04
Eric Selin, founder of Statichost.eu based in Stockholm, has launched a static website hosting service built entirely on European infrastructure. The platform avoids American providers like AWS and Cloudflare at every layer, from git-based deployment to content delivery.
statichost.eu
· 2026-09-04