What the June 2026 Threat Technique Catalog update means for your AWS environment
Security Blog
AWS CIRT's June 2026 Threat Technique Catalog update documents five new attack techniques and updates three existing ones based on real-world security incidents.
- EKS workload modification: Threat actors alter container images or pod specs to inject malicious code into running deployments
- Exploit public-facing applications on EKS: Exposed Kubernetes API servers and misconfigured ingress controllers enable lateral movement within clusters
- Assume root into organization member accounts: Compromised management accounts can assume root access in member accounts, bypassing local security controls
- Compute hijacking on EKS: Threat actors deploy cryptocurrency mining workloads that consume cluster resources at scale without resource quotas
- Invite accounts to unknown organization: Attackers move standalone accounts into attacker-controlled organizations to restrict legitimate owner access
- Updated S3 Object Collection, Compute Hijacking for ECS, and Role Assumption techniques with refined detection and mitigation guidance
These techniques exploit legitimate AWS functionality, requiring context-aware detection through CloudTrail and Kubernetes audit logs to identify malicious activity.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.