Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

aws.amazon.com

Latest Bulletins

Get the latest updates from Latest Bulletins directly as they happen.

Follow now 284 followers

Latest posts

Last updated about 22 hours ago

CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows

about 22 hours ago

Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation

1 day ago

Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools

2 days ago

Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands

2 days ago

Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection

2 days ago

Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool

5 days ago

Bulletin ID: 2026-069-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin

5 days ago

Bulletin ID: 2026-068-AWS Publication Date: 07/31/2026 11:00 AM PDT Please refer to...

Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react

5 days ago

Please refer to the article below for the most up-to-date and complete...

CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

13 days ago

Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

13 days ago

Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...

CVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure

13 days ago

Bulletin ID: 2026-063-AWS Scope: AWS Content Type: Important (requires attention) Publication Date...