Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • BuckHacker: a search engine that find hackable servers
  • Technology

BuckHacker: a search engine that find hackable servers

Do Son February 20, 2018 3 minutes read
BuckHacker
Add Daily CyberSecurity as a preferred source on Google

A new service aimed specifically at white hat hackers has been launched and a project called Buckhacker has created a Google-like search engine that discovers businesses inadvertently by browsing servers exposed to the Internet Leaked sensitive data that allows any user to search for non-secure data stored on Amazon Amazon Web Services (AWS) server buckets.

In fact, there has been a flood of data breaches in the past 2017, with many of the world’s leading companies storing customer and business data on AWS servers without password protection, which means that anyone who knows the exact address of a bucket can associate it Content to visit.

Accenture, WWE, AA, Dow Jones, and even the U.S. National Security Agency have all experienced server configuration errors and were blamed by public opinion for not following the most basic security protocols.

Often, these discoveries require a wide search by publicly available security research groups of publicly accessible servers on the Internet. Buckhacker significantly simplifies this process by allowing users to search AWS lists by using bucket names or file names that may be relevant to the target business. The developers of the project say it is about raising awareness of security rather than helping potential hacker groups.

Although the tool is not designed to be high, it does collect the results and store the information stored in the database for other users to see. Developers in the interview explained that “the goal of this project is to raise awareness of the security buckets, many businesses now suffer due to errors in the management of the bucket. The project is still in its infancy (we are trying to repair one of them some bugs).”

The Buckhacker project was not the first such tool until tools such as AWSBucketDump had allowed users to maliciously find out to expose AWS buckets; Google users could even visit specific server addresses if they knew exactly what to search for. However, Buckhacker is noteworthy because it is probably the easiest-to-use, user-friendly tooling available to date.

Mike Xu Richter, vice president of product management at Bitglass Security, said: “As attackers have easy access to this discovery tool, ensuring that the enterprise infrastructure is not open to the public should be one of the basic principles that must be followed by enterprise IT departments.”

At the same time as the new tool was unveiled, 119,000 U.S. Federal Express customers were also found to have leaked details including home addresses, e-mail addresses, and user’s driver’s license and passport details.

Mr. Richter said the courier company was just another grizzled victim of huge amounts of wealth and deep security but falling into the trap of the same basic but grave mistake.

Amazon pointed out in November 2017 that it will introduce default encryption for all new AWS servers that could theoretically prevent the recurrence of such a leak. However, users need to apply this encryption feature manually to all existing buckets, meaning that data stored on servers unknown to the business is still under serious threat.

Researchers have already realized the existence of this new tool on the Amazon site.

However, in this time,

Sorry guys, we are going offline for maintenance. We went online with the alpha version to early.

— BuckHacker (@thebuckhacker) February 14, 2018

Related coverage

  • Google to launch a new design for its Gmail web interface
  • Values Over Cash: Python Foundation Rejects $1.5M US Grant Over Anti-DEI Clause
  • Some Network Performance Tests for Windows Server 2016 and Linux
  • Microsoft Announces to Support JavaScript for Excel
  • China Accuses NVIDIA of Anti-Monopoly Violations
  • Windows Defender wins AV-Test TOP recommendation
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: BuckHacker

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105778CVSS 9.4
    A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of...
    📅 Updated: Oct 6, 2026
  • CVE-2026-94293CVSS 9.3
    An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all...
    📅 Updated: Oct 6, 2026
  • CVE-2026-56662CVSS 9.6
    GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51922CVSS 9.8
    agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51915CVSS 9.8
    TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51898CVSS 9.8
    sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
    📅 Updated: Oct 6, 2026
  • CVE-2026-51906CVSS 9.1
    In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers...
    📅 Updated: Oct 6, 2026
  • CVE-2026-96659CVSS 9.1
    A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.