Hackers Exploit AWS IAM Eventual Consistency to Establish Persistence
ID: 08afabe8-ce26-5854-b36d-cddb6131bd83
STIX ID: report--08afabe8-ce26-5854-b36d-cddb6131bd83
Feed Name: cybersecurityNews.com
OFFENSAI reported that AWS IAM's eventual consistency can create a short window (approximately 3–4 seconds) during which deleted access keys and other IAM changes are still effective, allowing an attacker to maintain or re-establish access by quickly creating keys or detaching controls; CloudTrail logs show the deletions but propagation lag enables persistence. The firm recommends account-level SCPs and revised playbooks; AWS acknowledged the behavior, applied development fixes and documentation updates, and no in-the-wild exploitation was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
