// Alert

AWS threat report

// AWSMEDIUM

AWS disclosed CVE-2026-15746, an SSRF vulnerability in the strands-agents-tools package (an open-source Python SDK for building AI agents). The elasticsearch_memory tool allows large language models to control connection parameters, enabling a crafted prompt to exfiltrate the operator's Elasticsearch API key to an attacker-controlled server. AWS recommends upgrading to version 0.7.0 or later and rotating all ELASTICSEARCH_API_KEY credentials as a precautionary measure.

// Get alerts for AWS