Find notable cyber news and cases, enriched with sources, timelines, and signals.

Publicly exposed training and demo apps in cloud environments are being abused at scale

Trend
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

Publicly exposed training and demo applications are showing up at scale in AWS, Azure, and GCP, turning lab systems into real cloud footholds. Researchers verified nearly 2,000 live instances, and about 20% already contained malicious artifacts such as crypto-mining, webshells, and persistence tools. The findings matter because these apps were often connected to privileged cloud identities, letting attackers move beyond the vulnerable application into broader infrastructure.

Related Happenings

Google Cloud Vertex AI SDK Python predictable bucket squatting security flaw

Vulnerability
H score1 First: 16.06.2026 22:05 Last: 16.06.2026 22:05 Sources 1

About this happening: Google Cloud Vertex AI SDK for Python had a predictable temporary bucket flaw that let an attacker hijack model uploads and reach code execution inside Google's servin...

Unit 42 Zealot proves autonomous cloud attack chaining in GCP

Technical Analysis
H score28 First: 23.04.2026 13:00 Last: 23.04.2026 13:00 Sources 1

About this happening: Unit 42's Zealot PoC shows autonomous AI can chain cloud attack stages in a live Google Cloud Platform environment, shrinking defender reaction time to minutes. The system...

XM Cyber maps eight validated AWS Bedrock attack vectors across connected enterprise integrations

Technical Analysis
H score26 First: 23.03.2026 13:55 Last: 23.03.2026 13:55 Sources 1

About this happening: XM Cyber mapped eight validated attack vectors in AWS Bedrock, showing how over-privileged permissions can expose logs, knowledge bases, agents, flows, guardrails, and...

AWS Bedrock AgentCore Code Interpreter DNS exfiltration and covert C2 in Sandbox Mode

Technical Analysis
H score25 First: 16.03.2026 15:00 Last: 16.03.2026 15:00 Sources 1

About this happening: Researchers demonstrated DNS-based exfiltration and covert C2 against AWS Bedrock AgentCore Code Interpreter, showing cloud AI code execution environments can still le...

Elastic Cloud SIEM stolen-data campaign

Campaign
H score41 First: 09.03.2026 17:45 Last: 09.03.2026 17:45 Sources 1

About this happening: The Elastic Cloud SIEM abuse campaign has been uncovered across dozens of organizations, turning a legitimate security platform into a stolen-data hub and increasing opera...

Timeline

  1. 11.02.2026 13:30 2 articles · 5mo ago

    Exposed training apps abused across cloud accounts

    Campaign Scope Update

    Pentera Labs identified a recurring cloud-abuse pattern in publicly exposed training and demo applications such as OWASP Juice Shop, DVWA, Hackazon, and bWAPP: nearly 2,000 live instances were verified, about 60% on customer-managed AWS, Azure, or GCP infrastructure, and roughly 20% contained malicious artifacts including crypto-mining, webshells, and persistence mechanisms. The exposed systems were often deployed with default configurations, minimal isolation, and overly permissive cloud roles, creating a foothold that could extend into broader cloud resources at organizations including Palo Alto, F5, and Cloudflare.

    Show sources