Home icon

What the June 2026 Threat Technique Catalog update means for your AWS environment

Security Blog



AWS CIRT's June 2026 Threat Technique Catalog update documents five new attack techniques and updates three existing ones based on real-world security incidents.

  • EKS workload modification: Threat actors alter container images or pod specs to inject malicious code into running deployments
  • Exploit public-facing applications on EKS: Exposed Kubernetes API servers and misconfigured ingress controllers enable lateral movement within clusters
  • Assume root into organization member accounts: Compromised management accounts can assume root access in member accounts, bypassing local security controls
  • Compute hijacking on EKS: Threat actors deploy cryptocurrency mining workloads that consume cluster resources at scale without resource quotas
  • Invite accounts to unknown organization: Attackers move standalone accounts into attacker-controlled organizations to restrict legitimate owner access
  • Updated S3 Object Collection, Compute Hijacking for ECS, and Role Assumption techniques with refined detection and mitigation guidance

These techniques exploit legitimate AWS functionality, requiring context-aware detection through CloudTrail and Kubernetes audit logs to identify malicious activity.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Apr 28
2026
What the March 2026 Threat Technique Catalog update means for your AWS environment
Jul 15
2026
ICYMI: June 2026 @AWS Security
Jun 8
2026
ICYMI: May 2026 @AWS Security
Jul 15
2026
This Month in AWS Observability: June 2026

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.