logo

Cloud misconfiguration has evolved and your controls haven’t

ID: ee2a3aed-039f-5bcd-bf2a-40d243ac9b12

STIX ID: report--ee2a3aed-039f-5bcd-bf2a-40d243ac9b12

Feed Name: Help Net Security

Threat Score
30/100

Date Published: 2026-03-20

Date Updated: 2026-04-28

Author: Help Net Security

...
...

The report outlines two AWS misconfigurations that can be abused by attackers: bucket name squatting (registering expected S3 bucket names to receive misrouted data or code) and a cross-service confused-deputy issue (resource policies that trust AWS services without restricting the source account). It recommends fixes including tying bucket names to account IDs and regions and adding condition keys to resource policies to lock trust to specific accounts or organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.