The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs

2026-06-02T20:51:52Z613095453a00e3e484dd56edb365cb8ee17bdc4ea83aab700a9bbf5384ac5238
attack-surface-managementawscloud-native-c2command-and-controlcontainerscredential-disclosuredirty-fragfedrampkuberneteslambda-function-urlslinux-kernellocal-privilege-escalationpatchingserverless-securitysspmthreat-huntingvulnerability-research

What happened

This collection highlights a trending shift to cloud-native command-and-control (C2) — exemplified by the HazyBeacon technique that weaponizes AWS Lambda Function URLs — alongside multiple high-impact Linux kernel local privilege escalations. HazyBeacon shows attackers using first‑party cloud hosting (Lambda function URLs) to host beacons and C2, evading traditional IP/domain-based defenses and complicating blocking and attribution. Separately, Qualys published CVE-2026-46333, a logic flaw in __ptrace_may_access() allowing local users to disclose sensitive files and gain root on many default L

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
613095453a00e3e484dd56edb365cb8ee17bdc4ea83aab700a9bbf5384ac5238
Enrichment time
2026-06-02T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs · Baitaphish