82% of companies unknowingly give 3rd parties access to all their cloud data
ID: 72786a38-d0ab-5754-964a-458d26b60e1e
STIX ID: report--72786a38-d0ab-5754-964a-458d26b60e1e
Feed Name: Wiz Blog
Wiz Research analyzed third‑party vendor IAM roles across 1,300 AWS accounts and 40+ vendors, finding pervasive over‑privilege: 82% grant highly privileged roles, 76% allow potential account takeover, and over 90% of teams were unaware of the risk. The report details subtle escalation paths via iam:PutRolePolicy, lambda:AddPermission, and misuse of AWS ReadOnlyAccess, and recommends enforcing least privilege, scoping permissions with tags/conditions, monitoring external roles, and replacing ReadOnlyAccess with safer alternatives such as ViewOnlyAccess.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
