Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories
2026-06-27T07:24:05Z•3346953f45d1f6afc51099d16fa04c9600745f48b23b8c4a0db92949d0df20a0
AI-threatsAPTAWSAkritesCISACVE-2026-12569GaslightKlueLinux FoundationPTC WindchillPolymarketRCEScattered SpiderTurlabackdoorcloudcredential-theftcryptocurrencydata-breachknown-exploited-vulnerabilitymacOSopen-source-securityrepositoriessupply-chainthird-party-compromise
What happened
A number of high-impact cyber incidents and security developments were reported: AWS patched an “Q” flaw that could enable cloud credential theft via malicious repositories; PTC Windchill remote code execution (CVE-2026-12569) has been observed in the wild and added to CISA’s Known Exploited Vulnerabilities catalog; roughly two dozen victims tied to the Klue–Salesforce breach have been identified; Polymarket lost about $3M after attackers abused a third‑party vendor compromise; Russian APT Turla deployed a new ‘StockStay’ backdoor against Ukrainian government and military targets. Other items:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 3346953f45d1f6afc51099d16fa04c9600745f48b23b8c4a0db92949d0df20a0
- Enrichment time
- 2026-06-27T07:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.