AWS patches SDK flaw enabling credential theft
Amazon Web Services patched a flaw across seven SDKs after security startup Pi Inc. discovered that a region input field could be manipulated to redirect API calls to attacker-controlled servers. By injecting a malicious string like @attacker.com# into the region parameter, researchers tricked SDKs into sending signed requests, and in some cases bearer tokens, to external hosts, yielding live AWS credentials.
Pi's platform identified roughly 2,500 instances of the same defect from a single bug report, and seven of seven tested third-party platforms were exploitable. AWS quietly patched the flaw with input validation but framed it as a defense-in-depth enhancement rather than a vulnerability, drawing criticism from Pi over the low CVE rating assigned only to the .NET SDK.
