[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fG0yq8JI_T9HBRmA74CizMzNGiqMxvPczV0rcI3liC8g":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"0851b1ba-a1ce-40d4-a722-297502f94898","teampcp-exploits-stolen-aws-credentials-to-expand-cloud-attack-surface","c42a5bb9-ed16-4920-b4e4-aa1d882727e3","TeamPCP Exploits Stolen AWS Credentials to Expand Cloud Attack Surface","The TeamPCP group successfully pivoted from compromising open-source software repositories to weaponizing stolen AWS credentials for cloud environment attacks. They used credential validation tools like TruffleHog to verify stolen credentials, then systematically enumerated AWS services, accessed secrets managers, and leveraged GitHub workflows and ECS Exec for code execution and data exfiltration. This attack demonstrates how compromised credentials from supply chain attacks can be monetized through collaboration with ransomware groups, creating a dangerous ecosystem of credential sharing and data theft.","**Immediate actions:**\n- Rotate all AWS access keys and API credentials immediately\n- Enable AWS CloudTrail logging across all regions and services\n- Implement AWS Config rules to detect unauthorized resource access\n\n**Long-term improvements:**\n- Enforce least privilege access policies with regular access reviews\n- Implement AWS IAM Identity Center with multi-factor authentication for all users\n- Deploy AWS GuardDuty for continuous threat detection and monitoring\n\n**Supply chain security:**\n- Scan all third-party dependencies and repositories for embedded credentials\n- Implement secrets scanning in CI\u002FCD pipelines before code commits\n- Use AWS Secrets Manager or Parameter Store instead of hardcoded credentials",[12,13,14,15,16,17,18],"CIS Control 5","CIS Control 6","NIST AC-2","NIST AC-3","NIST SR-3","NIST AU-2","AWS Well-Architected Security Pillar","published","2026-03-31T14:09:26.518403+00:00","2026-03-31T14:09:26.409+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fwww.securityweek.com\u002Fteampcp-moves-from-oss-to-aws-environments\u002F","teampcp-moves-from-oss-to-aws-environments","TeamPCP Moves From OSS to AWS Environments",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":34,"name":35,"slug":36,"description":37,"color":38},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]