ZeroHour
Datadog Security Labspublished ()ingested

Password spraying campaign targets AWS root user accounts across 150+ organizations

highThreat actor exploited in the wildimportance 68
AI summary · glm-5.3-flash

Datadog researchers observed a password spraying campaign attempting to authenticate as AWS root users across 150+ organizations.

Datadog Security Research observed a large-scale password spraying campaign attempting to authenticate as AWS root user accounts across more than 150 organizations. The campaign targeted root credentials rather than standard IAM users, and no confirmed compromises are stated in the report. Root account access would grant full control of affected AWS environments, making this a significant credential-attack campaign for cloud defenders.

  • Password spraying targeted AWS root user accounts, not IAM users
  • More than 150 organizations were targeted
  • Observed via Datadog Security Research telemetry
  • No confirmed compromise stated; root access would be high impact
Full article

Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.

This source does not provide full text. Read it at securitylabs.datadoghq.com.