Shadow Roles: AWS Defaults Can Lead to Service Takeover
ID: ee1ef3b8-6855-5d8d-9412-70e57b1e057c
STIX ID: report--ee1ef3b8-6855-5d8d-9412-70e57b1e057c
Feed Name: Aqua Security Blog
Aqua Security research reveals that default AWS service roles (e.g., SageMaker, Glue, EMR) and some open-source deployment defaults (e.g., Ray) were provisioned with overly broad S3 privileges (effectively AmazonS3FullAccess). Attackers can abuse these roles to locate and modify service-linked S3 assets (CloudFormation/CDK/Glue/SageMaker/EMR), enabling remote code execution, lateral movement, and potential full account takeover; the report includes PoC scenarios, coordinated disclosure to AWS, and remediation recommendations to scope IAM roles and limit S3 access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
