Urgent.News

One page, thousands of outlets. See who else covered it.

Editions โ–พ

Tech

Your Integrity Checks Are Watching the Wrong Layer

Ciao Amici ๐Ÿ‘‹ Quick story before we get into the weeds. Last week I took a patient health record sitting in Amazon S3, a file clearly stamped as regulated under HIPAA, and I changed its security label to "public." Anything reading that label would now happily treat protected health information as freely shareable. Here is the part that should make you put your coffee down. I never touched theโ€ฆ

S3 annotations introduced in June 2026 allow for attaching up to 1,000 structured metadata per object, up to 1 GB in size. Unlike tags and user metadata, annotations can be changed without rewriting the object and are queryable at scale via Apache Iceberg tables. While this feature enables attaching extensive context to objects, it also presents a security vulnerability.

Changing the security label of an S3 object does not alter its contents, making it impossible for integrity monitors to detect any modifications. An attacker could maliciously alter the context attached to an object without triggering any alarms, potentially exposing sensitive information. The author built a document classifier to test this vulnerability.

The classifier analyzes files and assigns sensitivity labels based on predefined rules, with the most restrictive rule taking precedence if multiple matches are found. If no matches are found, the default label is "internal." This approach ensures that files are treated with the necessary level of sensitivity, even when context is ambiguous.

Written by urgent.news from Dev.to's reporting โ€” not their text. Machine-written โ€” may contain errors; check the original before relying on it.

Read the original at dev.to โ†’

More in Tech

Cl0p widens data theft campaign across global firms

Cl0p has claimed a sweeping data-theft campaign affecting nearly 50 companies worldwide, placing Shell, Philips, GE and financial technology group Fiserv among the organisations named on theโ€ฆ

  • Cl0p cybercrime group targets nearly 50 global firms across industries
  • High-profile victims include Shell, Philips, GE, and Fiserv
  • Exploits vulnerabilities in PTC Windchill and FlexPLM systems

More from Monday 17 August โ†’