LIVE · cybersecurity feed
Live wire
Cisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UA

zeroday.news ·

Photo: Ajay Suresh from New York, NY, USA (CC BY 2.0) via Wikimedia Commons

Amazon Web Services (AWS) has confirmed the permanent loss of customer data in its Middle East (Bahrain) region, designated me-south-1, and in one availability zone of its Middle East (UAE) region, me-central-1. The announcement, made in two updates on September 15, comes six months after Iranian drone strikes impacted AWS infrastructure in the region.

For customers in Bahrain, AWS stated it is unable to restore access to resources and data hosted exclusively in the me-south-1 region. The company indicated that the damage in Bahrain affected multiple availability zones and surpassed the capacity of its redundancy measures. AWS has committed to providing a further update for Bahrain in early 2027.

In the UAE, the data loss is confined to a single availability zone, mec1-az2, within the me-central-1 region. AWS reported that it cannot restore access to resources and data stored exclusively in this specific zone. Work is ongoing for the other two availability zones in the UAE, mec1-az1 and mec1-az3, as well as for shared regional infrastructure. AWS expects to provide an update on service restoration in the UAE in the coming months.

The Iranian strikes, which began in early March, were reportedly in retaliation for a joint US-Israeli military campaign against Iran. Gulf states hosting American military bases, including the UAE and Bahrain, became targets.

AWS initially reported that two of its facilities in the UAE were directly struck. In Bahrain, a drone strike in close proximity to one of its facilities caused physical damage to the infrastructure. These initial strikes resulted in structural damage, power disruptions, and in some instances, required fire suppression activities that led to additional water damage.

The situation in Bahrain deteriorated in the weeks following the initial attacks. A second availability zone in the region was disrupted in April, leading to the entire me-south-1 region going offline.

AWS noted that most customers in both affected regions had already relocated their data prior to the losses becoming permanent. This was achieved by utilizing backups where available or by implementing alternative solutions to mitigate the impact of inaccessible data. AWS has also stated it has notified relevant authorities and continues to collaborate with them.

patchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Windows 11 24H2 Home and Pro reach end of support in October

Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]

vulnerabilityhigh

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

vulnerability

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

phishing

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page. The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Cre

malware

Chosen Brick, Iran’s Surveillance Malware

UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]

finance

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]