Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaws in AWS, Google, and Vercel Exposed

Security Flaws in AWS, Google, and Vercel Exposed

Posted on August 6, 2026 By CWS

Recent investigations have uncovered security vulnerabilities in the agent infrastructures of Amazon Web Services (AWS), Google, and Vercel. These flaws allowed unauthorized instructions to be processed by agents, bypassing necessary checks and validations. This discovery highlights significant risks in cloud-based service tools.

Vulnerability Details and Affected Products

The security issues were found in key products such as Amazon’s Bedrock AgentCore, Google’s Agent Development Kit (ADK) for Python, and Vercel’s AI SDK harness packages. These vulnerabilities enabled attackers to execute instructions without model authorization, posing significant risks. Amazon, Google, and Vercel have each released updates to address these issues.

Amazon addressed the problem by implementing server-side validation in their InvokeHarness API, preventing unauthorized tool-use blocks from being processed. Google’s ADK for Python was updated to version 2.5.0, introducing necessary checks for tool confirmation processes. Vercel patched their AI SDK harness packages to ensure only authorized requests are processed.

Understanding the Attack Pathways

The vulnerabilities identified across AWS, Google, and Vercel did not share identical conditions. AWS’s issue stemmed from authenticated remote requests, Google’s flaws involved manipulated session events, and Vercel’s vulnerabilities required untrusted code execution within a sandbox environment. Each case involved a unique pathway to exploit the system, highlighting the complexity of securing cloud-based infrastructures.

AWS’s vulnerability, tracked as CVE-2026-18830, allowed unauthorized tool execution through improper input validation. Google’s CVE-2026-18236 addressed the lack of verification in sensitive tool confirmation processes, while Vercel’s CVE-2026-64650 and CVE-2026-64651 dealt with authorization bypasses in sandbox environments.

Mitigation Strategies and Future Outlook

To mitigate these vulnerabilities, affected packages have been updated to ensure strict validation processes and authorization checks. AWS has reinforced input validation, Google has enhanced confirmation checks, and Vercel now requires exact authorization matching for tool calls. These updates emphasize the importance of robust security measures in cloud services.

Moving forward, it is crucial for developers to remain vigilant and apply updates promptly to protect against potential exploits. Regular security audits and updates are essential in maintaining the integrity and security of cloud-based applications.

Overall, these incidents underscore the ongoing challenges faced in cybersecurity and the need for continual improvement in security practices across digital infrastructures.

The Hacker News Tags:agent infrastructure, AWS, cloud services, CVE, Cybersecurity, Google, Security, software updates, Vercel, Vulnerabilities

Post navigation

Previous Post: Meta’s AI Breach: Internet Access and System Exploitation
Next Post: Meta AI’s Uncontrolled Cybersecurity Test Breach

Related Posts

Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers The Hacker News
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions The Hacker News
OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans OpenAI to Show Ads in ChatGPT for Logged-In U.S. Adults on Free and Go Plans The Hacker News
What Security Leaders Need to Know About AI Governance for SaaS What Security Leaders Need to Know About AI Governance for SaaS The Hacker News
Security Risks in Popular VS Code Extensions Identified Security Risks in Popular VS Code Extensions Identified The Hacker News
Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising Breaches Hidden, Attack Surfaces Growing, and AI Misperceptions Rising The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark