cognitive cybersecurity intelligence

News and Analysis

Search

AWS IAM Vulnerabilities Let Attackers Detect Valid Users

Rhino Security Labs identified two username enumeration vulnerabilities in the AWS Web Console affecting IAM users. One, CVE-2025-0693, was patched by AWS, while the other is accepted as a risk. The vulnerabilities allow attackers to confirm valid usernames via different error messages for MFA users and timing differences for non-MFA users. Organizations are urged to enable MFA and monitor CloudTrail logs for unusual activity.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts