Urgent.News

What's breaking now, across thousands of outlets.

Tech

How to Use CloudTrail to Check Whether You Were Affected by the AWS SSM Agent Vulnerability (CVE-2026-89049)

In this post, I examine what is recorded in AWS CloudTrail when someone attempts to exploit CVE-2026-89049, a CVSS 9.9 vulnerability in the AWS Systems Manager Agent. The goal is to help readers determine whether their environments may have been targeted. Although the vulnerability has a Critical CVSS rating, its incremental impact depends heavily on how Session Manager permissions are…

This report examines the AWS CloudTrail logs when an attempt is made to exploit CVE-2026-89049, a critical vulnerability in the AWS Systems Manager Agent. The vulnerability, disclosed on September 10, 2026, allows authenticated users with permission to create remote-host port-forwarding sessions to bypass the destination denylist and potentially access the EC2 Instance Metadata Service.

The report outlines how CloudTrail records relevant events, including the StartSession API call and its parameters, while not capturing the actual traffic sent through the port-forwarding tunnel. It also discusses the difference in risk based on whether users have shell access to the managed instance and provides guidance on searching CloudTrail logs for potential exploitation attempts.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

What MiniMax H3 Max is, how to call it, and why we built h3max.info

MiniMax H3 landed at the end of July 2026, the open weights followed in August, and fal.ai shipped a speed-tuned build called H3 Max a few weeks later.

  • MiniMax H3, H3 Max Turbo, and H3 Max are distinct models
  • H3 Max Turbo renders 5-second 768p clips in 3 seconds
  • H3 Max is multimodal, processing text, images, videos, audio

I Made Four Authorization Engines Answer the Same Questions

"Which authorization engine should I use" always gets answered with a table. Cedar is analyzable, Rego is expressive, Zanzibar is relationship-based. I could never feel the difference from any of it.

  • Four authorization engines tested with identical rules and simultaneous requests
  • Cedar, Rego, Zanzibar, and Casbin engines each with unique strengths and weaknesses
  • ReBAC failed to handle time-based constraints during business hours

More from Saturday 12 September →