
August 25, 2025
🥖 Palette Cleanser
Hello my lovelies,
This was a great week for AWS security content. I couldn't even fit it all in, so I cheated and put this wonderful series of Amazon Q bug write-ups and videos by Johann Rehberger here instead of Chef's Selections:
- Amazon Q Developer for VS Code Vulnerable to Invisible Prompt Injection
- Amazon Q Developer: Remote Code Execution with Prompt Injection
- Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection
Johann has been doing a "month of AI bugs," publishing an AI vulnerability every day in August.
Have feedback about AWS Security Digest? Tell us here. This issue is also available to share online.
📋 Chef's selections
-
Using AWS Certificate Manager as a covert exfiltration mechanism by Costas Kourmpoglou
This week in cheeky exfiltration tactics: attackers can turn AWS Certificate Manager into a covert storage service by abusing the import-certificate API and stuffing payloads into the deprecated "nsComment" X.509 extension. According to Costas, it’s possible to smuggle up to 2 MB per cert (~7.5 GB/year) straight through ACM’s public endpoints. Since CloudTrail only logs “request too large” without the payload, the only way to catch it is with TLS-breaking proxy inspection.
-
Another ECS Privilege Escalation Path by Mohit Gupta, Tom Taylor-MacLean
Mohit and Tom found a new privilege escalation path starting from a compromised EC2 instance. With permissions like "ecs:StartTask" and "ecs:RegisterContainerInstance," they were able to self-register the EC2 into an ECS cluster, override the task definition’s start command, and then hit "169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" to retrieve task credentials. In their tests, even with "iam:PassRole" tightly scoped, this technique still opened a path to higher privileges, such as accessing Secrets Manager.
-
Evading Detection with Public S3 Buckets and Potential Data Exfiltration in AWS by Jason Kao
Jason found that AWS Trusted Advisor could be tricked into marking public S3 buckets as “secure” by adding bucket policies that deny checks like "s3:GetBucketPublicAccessBlock" or "s3:GetBucketAcl." In his testing, this let buckets remain world-readable via "s3:GetObject" while Trusted Advisor still reported green. He reported the issue in May 2025, and it has since been fixed.
-
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer by Nick Frichette, Brandon Dossantos
Simple but effective offensive security research is the best. Attackers could quietly enumerate AWS accounts by calling "resource-explorer-2:ListResources," which until July 2025 didn’t log to CloudTrail by default. Because the API laundered enumeration through Resource Explorer’s service-linked role, it returned a full inventory without generating the usual noisy "List*" or "Describe*" events. After their report, AWS reclassified "ListResources" as a management event, closing off this blind spot.
🥗 AWS security blogs
- 📣 Amazon Verified Permissions now supports Cedar 4.5
- 📣 AWS Security Incident Response introduces integrations with ITSM
- 📣 AWS Security Incident Response achieves HITRUST Certification
- Building resilient and secure game backends with Amazon CloudFront by Serge Poueme
- Securing hybrid workloads using Amazon Route 53 Resolver DNS Firewall by Yaniv Rozenboim
- AWS successfully completed its 2024-25 NHS DSPT assessment by Tariro Dongo
🍛 Reddit threads on r/aws
💸 Sponsor shoutout

Meet Pleri: your AI-powered cloud security teammate. She’s not a chatbot. Pleri proactively finds meaningful security work and fixes issues before they become problems.
Learn more about Pleri and see her in action.
🤖 Dessert
Dessert is made by robots, for those that enjoy the industrial content.
🧁 IAM permission changes
🍪 API changes
- AWS Elemental MediaLive
- Amazon Q Connect
- Amazon SageMaker Service
- Synthetics
- AWS WAFV2
- Amazon GameLift Streams
- AWS Glue
- Amazon Bedrock Runtime
- Amazon Cognito Identity Provider
- Amazon DataZone
- Amazon Elastic Kubernetes Service
- Amazon Kinesis Analytics
- Amazon Pinpoint SMS Voice V2
- Amazon SageMaker Service
- AWS Clean Rooms Service
- Amazon Elastic Compute Cloud
- Amazon Polly
- AWS Billing and Cost Management Dashboards
- Amazon Connect Service
- Amazon Connect Participant Service
- AWS S3 Control
- Amazon SageMaker Service
🍹 IAM managed policy changes
- AmazonAuroraDSQLFullAccess
- AmazonAuroraDSQLConsoleFullAccess
- AmazonSageMakerHyperPodObservabilityAdminAccess
- AWSBillingReadOnlyAccess
- AmazonSageMakerHyperPodTrainingOperatorAccess
- SageMakerStudioDomainExecutionRolePolicy
- SageMakerStudioUserIAMConsolePolicy
- SageMakerStudioAdminIAMConsolePolicy
- SageMakerStudioUserIAMPermissiveExecutionPolicy
- SageMakerStudioUserIAMDefaultExecutionPolicy
- SageMakerStudioAdminIAMPermissiveExecutionPolicy
- SageMakerStudioAdminIAMDefaultExecutionPolicy
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
- CVE-2025-9162
- CVE-2025-9187
- CVE-2025-9183
- CVE-2025-9179
- CVE-2025-38553
- CVE-2025-38609
- CVE-2025-8364
- CVE-2025-9185
- CVE-2025-38587
- CVE-2025-9181
- CVE-2025-38573
- CVE-2025-38568
- CVE-2025-9182
- CVE-2025-9184
- CVE-2025-38593
- CVE-2025-9180
- CVE-2025-38589
- CVE-2025-38557
- CVE-2025-38555
- CVE-2025-38572
- CVE-2025-38588
- CVE-2025-9186
📺 AWS security bulletins
-
No bulletins this week.
🚬 Security documentation changes
- AmazonECS Documentation Update
- AmazonECS Documentation Update
- AmazonECS Documentation Update
- apigateway Documentation Update
- batch Documentation Update
- batch Documentation Update
- batch Documentation Update
- clean-rooms Documentation Update
- clean-rooms Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- controltower Documentation Update
- drs Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- eks Documentation Update
- emr Documentation Update
- emr Documentation Update
- emr Documentation Update
- emr Documentation Update
- emr Documentation Update
- emr Documentation Update
- eventbridge Documentation Update
- glue Documentation Update
- greengrass Documentation Update
- guardduty Documentation Update
- guardduty Documentation Update
- inspector Documentation Update
- inspector Documentation Update
- iot Documentation Update
- iot Documentation Update
- mediaconnect Documentation Update
- transfer Documentation Update
- transfer Documentation Update
- transfer Documentation Update
- vpn Documentation Update
- athena Documentation Update
- athena Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update
- cli Documentation Update