AWS News - 2025-12-15
2025-12-15
最終更新: 2026-01-17 00:23:07 JST
AI による概要
この日はニュース 1 件、セキュリティブログ 2 件、セキュリティ速報 1 件が公開され、脅威インテリジェンスが中心テーマとなりました。News Blog では 2025 年を振り返る週刊まとめ (ECS、CloudWatch、Cognito など) が公開されました。セキュリティブログでは、近年の高プロファイルな npm サプライチェーン脅威キャンペーンへの対応から AWS セキュリティが学んだ教訓を共有する記事と、Amazon 脅威インテリジェンスがロシアの国家支援サイバー脅威グループによる西側重要インフラを標的とした長年のキャンペーンを特定した記事が公開されました。後者では、設定ミスの顧客ネットワークエッジデバイスが主要な初期侵入経路となる戦術的転換が報告されています。セキュリティ速報 AWS-2025-031 では、Harmonix on AWS (EKS) の過度に寛容な IAM 信頼ポリシー (CVE-2025-14503) による権限昇格の可能性が告知されました。
主要トピック
2025 年振り返り: Weekly Roundup で ECS/CloudWatch/Cognito などの動向を総括
サプライチェーン脅威: npm サプライチェーン攻撃キャンペーン対応から AWS セキュリティが得た教訓
国家支援脅威: ロシアの脅威グループが西側重要インフラを標的、エッジデバイスの設定ミスを主要侵入経路に
セキュリティ速報: Harmonix on AWS EKS の過度に寛容な IAM 信頼ポリシー (CVE-2025-14503, AWS-2025-031)
AWS News Blog
AWS Weekly Roundup: Amazon ECS, Amazon CloudWatch, Amazon Cognito and more (December 15, 2025)
- Link: https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ecs-amazon-cloudwatch-amazon-cognito-and-more-december-15-2025/
- Published: 2025-12-15 00:00:00
- Fetched: 2025-12-15 00:00:00
AWS Security Blog
What AWS Security learned from responding to recent npm supply chain threat campaigns
- Link: https://aws.amazon.com/blogs/security/what-aws-security-learned-from-responding-to-recent-npm-supply-chain-threat-campaigns/
- Published: 2025-12-15 00:00:00
- Fetched: 2025-12-15 00:00:00
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure
- Link: https://aws.amazon.com/blogs/security/amazon-threat-intelligence-identifies-russian-cyber-threat-group-targeting-western-critical-infrastructure/
- Published: 2025-12-15 00:00:00
- Fetched: 2025-12-15 00:00:00
AWS Security Bulletins
Overly Permissive Trust Policy in Harmonix on AWS EKS
- Link: https://aws.amazon.com/security/security-bulletins/rss/aws-2025-031/
- Published: 2025-12-15 00:00:00
- Fetched: 2025-12-15 00:00:00
Bulletin ID: AWS-2025-031
Scope: AWS
Content Type: Informational
Publication Date: 2025/12/15 11:45 AM PST
Description:
Harmonix on AWS is an open source reference architecture and implementation of a Developer Platform that extends the CNCF Backstage project. We identified CVE-2025-14503 where an overly-permissive IAM trust policy in the Harmonix on AWS framework may allow authenticated users to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which may enable any account principal with sts:AssumeRole permissions to assume the role with administrative privileges.
Resolution:
v0.3.0 through v0.4.1