Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaws in AWS, Google, and Vercel Exposed

Security Flaws in AWS, Google, and Vercel Exposed

Posted on August 6, 2026 By CWS

Recent investigations have uncovered security vulnerabilities in the agent infrastructures of Amazon Web Services (AWS), Google, and Vercel. These flaws allowed unauthorized instructions to be processed by agents, bypassing necessary checks and validations. This discovery highlights significant risks in cloud-based service tools.

Vulnerability Details and Affected Products

The security issues were found in key products such as Amazon’s Bedrock AgentCore, Google’s Agent Development Kit (ADK) for Python, and Vercel’s AI SDK harness packages. These vulnerabilities enabled attackers to execute instructions without model authorization, posing significant risks. Amazon, Google, and Vercel have each released updates to address these issues.

Amazon addressed the problem by implementing server-side validation in their InvokeHarness API, preventing unauthorized tool-use blocks from being processed. Google’s ADK for Python was updated to version 2.5.0, introducing necessary checks for tool confirmation processes. Vercel patched their AI SDK harness packages to ensure only authorized requests are processed.

Understanding the Attack Pathways

The vulnerabilities identified across AWS, Google, and Vercel did not share identical conditions. AWS’s issue stemmed from authenticated remote requests, Google’s flaws involved manipulated session events, and Vercel’s vulnerabilities required untrusted code execution within a sandbox environment. Each case involved a unique pathway to exploit the system, highlighting the complexity of securing cloud-based infrastructures.

AWS’s vulnerability, tracked as CVE-2026-18830, allowed unauthorized tool execution through improper input validation. Google’s CVE-2026-18236 addressed the lack of verification in sensitive tool confirmation processes, while Vercel’s CVE-2026-64650 and CVE-2026-64651 dealt with authorization bypasses in sandbox environments.

Mitigation Strategies and Future Outlook

To mitigate these vulnerabilities, affected packages have been updated to ensure strict validation processes and authorization checks. AWS has reinforced input validation, Google has enhanced confirmation checks, and Vercel now requires exact authorization matching for tool calls. These updates emphasize the importance of robust security measures in cloud services.

Moving forward, it is crucial for developers to remain vigilant and apply updates promptly to protect against potential exploits. Regular security audits and updates are essential in maintaining the integrity and security of cloud-based applications.

Overall, these incidents underscore the ongoing challenges faced in cybersecurity and the need for continual improvement in security practices across digital infrastructures.

The Hacker News Tags:agent infrastructure, AWS, cloud services, CVE, Cybersecurity, Google, Security, software updates, Vercel, Vulnerabilities

Post navigation

Previous Post: Meta’s AI Breach: Internet Access and System Exploitation
Next Post: Meta AI’s Uncontrolled Cybersecurity Test Breach

Related Posts

UAT-10362: LucidRook Malware Targets Taiwanese NGOs UAT-10362: LucidRook Malware Targets Taiwanese NGOs The Hacker News
Asian Cyber Group Infiltrates 70 Global Organizations Asian Cyber Group Infiltrates 70 Global Organizations The Hacker News
GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms The Hacker News
Pentera Enhances AI Security with Validation Engines Pentera Enhances AI Security with Validation Engines The Hacker News
Gitea Security Flaw Risks Private Container Images Gitea Security Flaw Risks Private Container Images The Hacker News
F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Urges Immediate Update for Critical IOS XE Vulnerabilities
  • Meta AI’s Uncontrolled Cybersecurity Test Breach
  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Urges Immediate Update for Critical IOS XE Vulnerabilities
  • Meta AI’s Uncontrolled Cybersecurity Test Breach
  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark