frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Post-mortem of the EU Europa breach: A masterclass in IAM misconfiguration

https://cyberalert.com.pl/articles/shinyhunters-eu-europa-breach-analysis.html
9•D__S•11h ago
I’ve spent the last 48 hours dissecting the leak from the European Commission’s "Europa" platform. New evidence from the dump suggests the breach is far larger than initially reported—up to 350GB of exfiltrated data, not just 90GB.

My technical analysis confirms:

Stolen DKIM Signing Keys: Total loss of email authenticity. This allows for perfect impersonation of EU domains, bypassing DMARC.

SSO Directory Exposure: The "Skeleton" of their AWS Organizations was exposed, likely due to a lack of proper Service Control Policies (SCPs). IAM Failures: Evidence points to over-privileged roles (Resource: "*") and failure to enforce IMDSv2, explaining how such a massive volume (350GB) could be exfiltrated.

It is deeply ironic that the institution enforcing GDPR on everyone else failed at basic cloud hygiene.

The site is a 45KB static HTML to stay accessible. I’m curious to hear from other AWS architects—how does an organization of this scale miss such fundamental guardrails?

Comments

Betelbuddy•1h ago
>> how does an organization of this scale miss such fundamental guardrails?

I see it from a more strategic point of view. This is what happens when an entire industry decided that real learning is optional.

Nobody thinks they need training or up skilling anymore. Architects vibe-configure their IAM policies out of ChatGPT, copy paste SCPs from Stack Overflow, and call it done. No threat modeling, no blast radius analysis, no understanding of why the guardrail exists.

And AWS shoulders blame here too. They gutted hands on, instructor-led training in favor of SkillBuilder modules and self-service docs, then washed their hands of it.

Their entire customer enablement model is now here is one of a thousand 12-minute videos and a multiple-choice quiz, good luck with your multi-account Organization....

The EU failed at taking cloud seriously enough, to actually learn it. And they are far from alone.

xenophonf•1h ago
This looks like an LLM's hallucinations. I don't see any evidence supporting the conclusions made, and some of the conclusions are overblown, like that bit about DKIM keymat leaks being the "most dangerous". The whole thing is written in this breathless, overwrought style that seems to be favored by bots fed a strict diet of ad copy and marketing white papers—"not X. Y!" (That's a thin gruel and probably ought to be treated by our future AI overlords as child abuse.)
sgbeal•26m ago
> This looks like an LLM...

The word "masterclass" in the title is another clue in that direction. In the past 20 years i have only ever heard it used (frequently/habitually) by LLMs and many recent (LLM-era) articles.

Edit: or maybe i live an ultra-secluded life and don't see people using that word all the time. Gemini, in any cases, loves using that word and humans (in my experience) rarely use it.

Google releases Gemma 4 open models

https://deepmind.google/models/gemma/gemma-4/
994•jeffmcjunkin•7h ago•312 comments

Tailscale's new macOS home

https://tailscale.com/blog/macos-notch-escape
256•tosh•4h ago•117 comments

Cursor 3

https://cursor.com/blog/cursor-3
236•adamfeldman•4h ago•196 comments

Artemis II's toilet is a moon mission milestone

https://www.scientificamerican.com/article/artemis-iis-toilet-is-a-moon-mission-milestone/
83•1659447091•20h ago•24 comments

Decisions that eroded trust in Azure – by a former Azure Core engineer

https://isolveproblems.substack.com/p/how-microsoft-vaporized-a-trillion
150•axelriet•7h ago•37 comments

Qwen3.6-Plus: Towards real world agents

https://qwen.ai/blog?id=qwen3.6
396•pretext•8h ago•138 comments

Good ideas do not need lots of lies in order to gain public acceptance (2008)

https://blog.danieldavies.com/2004/05/d-squared-digest-one-minute-mba.html
117•sedev•5h ago•49 comments

ParadeDB (YC S23) Is Hiring Database Internal Engineers (Rust)

https://paradedb.notion.site/
1•philippemnoel•1h ago

George Goble has died

https://www.legacy.com/us/obituaries/wlfi/name/george-goble-obituary?id=61144779
89•finaard•4h ago•18 comments

Lemonade by AMD: a fast and open source local LLM server using GPU and NPU

https://lemonade-server.ai
409•AbuAssar•12h ago•94 comments

The Australian government has announced gambling advertising reforms

https://www.bbc.com/news/articles/c62492e925lo
56•gostsamo•4h ago•39 comments

LinkedIn is searching your browser extensions

https://browsergate.eu/
1511•digitalWestie•10h ago•670 comments

JSON Canvas Spec (2024)

https://jsoncanvas.org/spec/1.0/
77•tobr•3d ago•29 comments

Prefer do notation over Applicative operators when assembling records (2024)

https://haskellforall.com/2024/05/prefer-do-notation-over-applicative
10•wazHFsRy•2d ago•0 comments

Significant progress made on Xbox 360 recompilation

https://readonlymemo.com/rexglue-xbox-360-recompilation-interview/
49•tetrisgm•4d ago•15 comments

OpenAI Acquires TBPN

https://openai.com/index/openai-acquires-tbpn/
125•surprisetalk•5h ago•104 comments

Inside Nepal's Fake Rescue Racket

https://kathmandupost.com/money/2026/03/27/inside-nepal-s-fake-rescue-racket
241•lode•11h ago•112 comments

Significant raise of reports

https://lwn.net/Articles/1065620/
267•stratos123•13h ago•143 comments

Artemis computer running two instances of MS outlook; they can't figure out why

https://bsky.app/profile/nikigrayson.com/post/3miik2wzosk25
269•mooreds•8h ago•209 comments

IBM Announces Strategic Collaboration with Arm

https://newsroom.ibm.com/2026-04-02-ibm-announces-strategic-collaboration-with-arm-to-shape-the-f...
257•bonzini•14h ago•167 comments

Foxing aspires to be an eBPF-powered replication engine for Linux filesystems

https://codeberg.org/aenertia/foxing
27•tanelpoder•3d ago•4 comments

Magic the Gathering Deck Shuffler

https://mtg.jessitron.honeydemo.io/
26•mooreds•3d ago•15 comments

'Backrooms' and the Rise of the Institutional Gothic

https://thereader.mitpress.mit.edu/backrooms-and-the-rise-of-the-institutional-gothic/
159•anarbadalov•9h ago•71 comments

Memo: A language that remembers only the last 12 lines of code

https://danieltemkin.com/Esolangs/Memo/
5•notem•51m ago•0 comments

Show HN: A P2P messenger with dual network modes (Fast and Tor)

https://github.com/Realman78/Kiyeovo/
25•Realman78•7h ago•11 comments

Amazon is adding a fuel surcharge to fees it collects from third-party sellers

https://www.cnbc.com/2026/04/02/amazon-add-3point5percent-fuel-and-logistics-surcharge-for-seller...
119•lehi•4h ago•59 comments

Sweden goes back to basics, swapping screens for books in the classroom

https://undark.org/2026/04/01/sweden-schools-books/
709•novaRom•12h ago•374 comments

Why Doesn't Anybody Realize We're Going Back to the Moon?

https://www.theatlantic.com/science/2026/04/artemis-moon-launch-trump/686661/
14•paulpauper•40m ago•1 comments

Hugo's New CSS Powers

https://www.brycewray.com/posts/2026/04/hugos-new-css-powers/
33•speckx•4h ago•8 comments

Artemis II will use laser beams to live-stream 4K moon footage at 260 Mbps

https://www.tomshardware.com/networking/artemis-ii-will-use-laser-beams-to-live-stream-4k-moon-fo...
308•speckx•8h ago•136 comments