Attackers are expanding access through Amazon Cognito
ID: 5571c9e8-c811-5005-8d13-870d03cff16a
STIX ID: report--5571c9e8-c811-5005-8d13-870d03cff16a
Feed Name: Expel Blog
Expel observed attackers exploiting misconfigured Amazon Cognito deployments that exposed identity pool IDs and allowed token-exchange for temporary AWS credentials, enabling direct CLI/programmatic access to the AWS control plane; the report describes the attack flow, SOC findings (hundreds of API calls, attempts across ~50 services, many AccessDenied responses), detection indicators (Cognito-assumed role names, ASIA access key prefixes, unusual User-Agent values), and mitigations (harden Cognito IAM policies and avoid exposing identity pool IDs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
