logo

Fortifying Your Cloud Against Cross-Service Confused Deputy Attacks

ID: b19158fe-d9ef-50a9-9365-0b27e24f859a

STIX ID: report--b19158fe-d9ef-50a9-9365-0b27e24f859a

Feed Name: Qualys Blog

Threat Score
45/100

Date Published: 2025-07-24

Date Updated: 2026-04-28

Author: Nehal Baviskar

...
...

This report describes Cross-Service Confused Deputy attacks in AWS—particularly how ELB and other services can be abused via overly permissive S3 bucket policies to write (and potentially manipulate) logs in a victim's bucket—provides an attack path, maps to MITRE ATT&CK techniques, outlines impacts such as log integrity loss and compliance risk, and recommends mitigations like strict resource ARNs, aws:SourceAccount conditions, encryption, object lock, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.