What the March 2026 Threat Technique Catalog update means for your AWS environment
ID: 4b7fd1af-5b9b-5c5f-8153-231df0001b14
STIX ID: report--4b7fd1af-5b9b-5c5f-8153-231df0001b14
Feed Name: AWS Security Blog
Threat Score
The AWS CIRT March 2026 update to the Threat Technique Catalog for AWS describes three observed cloud attack techniques—Cognito refresh token abuse (long-lived refresh tokens used for invisible persistence), AMI image deregistration (removing recovery 'golden images'), and updating role trust policies via UpdateAssumeRolePolicy (adding external principals for stealthy privilege escalation)—and provides detection and mitigation guidance for each.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
