Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research
ID: 16a42ac2-d01e-58e3-bc8d-d6c14bf2e133
STIX ID: report--16a42ac2-d01e-58e3-bc8d-d6c14bf2e133
Feed Name: Datadog Security Labs
Threat Score
Datadog security researchers discovered CloudTrail bypass issues in AWS Service Catalog (via beta/gamma endpoints) and a logging omission in AWS Control Tower (AWSBlackbeardService) that allowed API read and write actions to be performed without corresponding CloudTrail logs; AWS was notified, implemented fixes for both services, and reported no evidence of customer impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
