Roles Here? Roles There? Roles Anywhere: Exploring the Security of AWS IAM Roles Anywhere
ID: 0ced38da-93c3-594c-9beb-bfbb2fa33d65
STIX ID: report--0ced38da-93c3-594c-9beb-bfbb2fa33d65
Feed Name: Palo Alto Networks Unit 42
This article examines how default configurations of AWS IAM Roles Anywhere can expose organizations to risk by allowing any trust anchor in the same region to assume roles, enabling lateral access if a certificate or Roles Anywhere permissions are compromised. It details attacker methods to discover required ARNs via Roles Anywhere list APIs and CloudTrail logs, and provides practical mitigations: enforce trust policy conditions (e.g., aws:SourceArn and certificate attribute mapping), prefer ACM-PCA trust anchors, apply least privilege (including session policies), and continuously monitor/alert on trust anchor and profile changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
