logo

Hackers Exploit AWS IAM Eventual Consistency to Establish Persistence

ID: 08afabe8-ce26-5854-b36d-cddb6131bd83

STIX ID: report--08afabe8-ce26-5854-b36d-cddb6131bd83

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Guru Baran

...
...

OFFENSAI reported that AWS IAM's eventual consistency can create a short window (approximately 3–4 seconds) during which deleted access keys and other IAM changes are still effective, allowing an attacker to maintain or re-establish access by quickly creating keys or detaching controls; CloudTrail logs show the deletions but propagation lag enables persistence. The firm recommends account-level SCPs and revised playbooks; AWS acknowledged the behavior, applied development fixes and documentation updates, and no in-the-wild exploitation was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.