The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs
2026-06-02T20:51:52Z•613095453a00e3e484dd56edb365cb8ee17bdc4ea83aab700a9bbf5384ac5238
attack-surface-managementawscloud-native-c2command-and-controlcontainerscredential-disclosuredirty-fragfedrampkuberneteslambda-function-urlslinux-kernellocal-privilege-escalationpatchingserverless-securitysspmthreat-huntingvulnerability-research
What happened
This collection highlights a trending shift to cloud-native command-and-control (C2) — exemplified by the HazyBeacon technique that weaponizes AWS Lambda Function URLs — alongside multiple high-impact Linux kernel local privilege escalations. HazyBeacon shows attackers using first‑party cloud hosting (Lambda function URLs) to host beacons and C2, evading traditional IP/domain-based defenses and complicating blocking and attribution. Separately, Qualys published CVE-2026-46333, a logic flaw in __ptrace_may_access() allowing local users to disclose sensitive files and gain root on many default L
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- 613095453a00e3e484dd56edb365cb8ee17bdc4ea83aab700a9bbf5384ac5238
- Enrichment time
- 2026-06-02T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.