Issue #277

Monday · September 07, 2026

๐Ÿฅ– Palate Cleanser

fwd:cloudsec Europe is on today and tomorrow in London, and I'm sure it will be an awesome event. Both days are streamed if you didn't make it over, day one and day two. Selfishly, what I'm really looking forward to is the flurry of blog posts that follows.

Act Security bought Cloud Copilot and David Kerber went with it. If you use iam-collect, iam-lens, iam-simulate or iam-expand, they moved to the act-security-labs org on 1 September and they are still AGPL-3.0. They are bundled now as Amphi with a browser UI and no signup. The small loss is that iam.cloudcopilot.io now 302s to the corporate site, so the independent blog is gone, and the posts I ran on Policy Tester in issue 192, fantastic AWS policies in 229 and testing S3 ABAC with iam-lens in 240 all live there now.

Reminder that nominations for the Top 10 AWS Security Research of 2026 close on 30 September. No login, no email address, self-nominations welcome, and I would much rather sift through too many than miss the good stuff. Go put something in.

๐Ÿ“‹ Chef's selections

Reading other AWS accounts' SQL on Amazon Athena

by Act Research

Athena, the query service for S3, has an engine called Trino. Trino ships a system.runtime.queries table that lists recently executed queries, and on shared infrastructure "recently executed" means everybody's. Asking for the system catalog inside the SQL gets you "Queries of this type are not supported", but nobody was checking the same request's QueryExecutionContext, so you leave the catalog out of the SQL, pass Catalog=system as a parameter alongside it, and the query runs. What comes back is other tenants' actual query text, which means their account IDs and whatever they inlined into a WHERE or an INSERT. Across 200 runs by Act Security, 2,590 of 2,794 rows belonged to somebody else, and in a second round 102 of 109 runs caught at least one other account. It was reported on 6 August 2026, the call was disabled on the 8th, and every region fixed by the 10th, which is genuinely fast work. No CVE or bulletin though? However, AWS did publish a bulletin last month for an Athena federated connector template that leaked Secrets Manager secrets in your own account. ๐Ÿคท

Password spraying campaign targets AWS root user accounts across 150+ organizations

by Martin McCloskey

From 24 July to 23 August somebody worked through the root user of more than 150 organisations, a median of two attempts each and up to eight, proxied through hosting and residential IPs across a spread of countries and ASNs. Apparently nothing worked. A failed root ConsoleLogin requires the root account's email address, so whoever this is either already holds a list of root emails or found them by grinding through candidates. I wonder how big the full attack was outside of DD's visibility. Root MFA has been mandatory since June 2025 but you should still be alerting on ConsoleLogin with userIdentity.type of Root, and if you have not moved to centralized root access with short-lived AssumeRoot sessions and an SCP shutting the rest down, this is the nudge. Neither of those covers your management account root though, which still needs its own answer.

๐Ÿฅ— AWS security blogs

๐Ÿ› Reddit threads on r/aws


๐Ÿค– Dessert

Every machine-tracked change this week. Nobody else assembles this.

๐Ÿง IAM permission changes

๐Ÿช API changes

๐Ÿน IAM managed policy changes

โ˜• CloudFormation resource changes

๐ŸŽฎ Amazon Linux vulnerabilities

๐Ÿ“บ AWS security bulletins

๐Ÿšฌ Security documentation changes

No changes this week.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.