Amazon Web Services (AWS) has fixed a critical flaw in its software development kits that could lead to credential theft. The issue was identified by product security startup Pi Inc. and affected 2,500 instances across multiple AWS SDKs. The flaw stemmed from the way the SDK built hostnames, leading to security vulnerabilities.