Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/aws/aws-ops-wheel

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Bulletin ID: 2026-018-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/24 09:15 AM PDT Description: AWS Ops Wheel is an open-source tool that helps teams make random selections using a virtual spinning wheel, deployed into customer AWS accounts via CloudFormation. CVE-2026-6911 relates to an issue where JWT token signature verification was not enforced in the v2 API. CVE-2026-6912 relates to an issue in the v2 Cognito User Pool configuration where attribute write permissions were insufficiently restricted. Impacted versions: AWS Ops Wheel v2 deployments PR-163 and earlier Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion

CVE-2026-6912 is a high-severity vulnerability in AWS Ops Wheel affecting the Cognito User Pool configuration. It allows remote authenticated users to escalate privileges to deployment admin by exploiting improper control over dynamically-determined object attributes via a crafted UpdateUserAttributes API call. This enables attackers to set the custom:deployment_admin attribute and manage Cognito user accounts. The vulnerability is present before pull request #165 and affects version 0 of AWS Ops Wheel. AWS manages remediation for this cloud service and has released a fix. Users should redeploy from the updated repository and patch any forked or derivative code accordingly.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:github/aws/aws-ops-wheel
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses