AWS has made AWS Management Console Private Access generally available, enabling organizations to route supported console traffic through AWS PrivateLink interface VPC endpoints rather than the public internet. The service supports console authentication, static assets, console-only APIs, and supported AWS service console traffic, allowing administrators in internet-isolated VPCs to access the console through private network paths.
Deployments require VPC endpoints for the AWS Management Console and sign-in services, with a console-static endpoint also required for VPCs without internet connectivity; separate PrivateLink endpoints remain necessary for AWS services accessed through their consoles. Organizations can enforce access boundaries with endpoint policies, sign-in resource control policies, resource-based policies, and service control policies. AWS cautioned that initial IAM Identity Center SSO authentication is not supported through these endpoints and still requires internet access.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
AWS initially launched AWS Management Console Private Access, though console static assets and console-only APIs still required internet connectivity at that time.
AWS made AWS Management Console Private Access generally available in all commercial AWS Regions for a select set of supported service consoles, enabling supported console traffic to use AWS PrivateLink VPC endpoints without public-internet routing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceaws.amazon.com
Open sourcedocs.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.