Issue #280

Monday · September 28, 2026

🥖 Palate Cleanser

I've been hassling you for months now. This is your last chance to nominate research for the AWS Security Digest Top 10. Nominations close this Wednesday, 30 September. Results will be announced on 28 October, and I'm going to convince Eduard to send Milo to the winners.

The fwd:cloudsec Europe individual talk videos went live on Thursday and the whole playlist is worth a scroll. The list includes these AWS-related presentations:

📋 Chef's selections

What IAM Sees That You Don't

by Dan Gansel

This is so cool. Every AWS API call carries a request context, a set of facts like the caller's IP that your policy conditions are checked against. AWS documents what's in it, but the list is incomplete. Dan turned session policies into a yes-or-no oracle, threw about 36 million guessed key names at IAM, and found 36 that the engine already evaluates but AWS has never documented. My favourite is aws:ResourceOrgMasterAccountId, which allows enumeration of the management account ID behind a public resource. In theory, you should be able to drop some of these keys into the Conditional Love tool Plerion published a while back.

AWS Managed Policy Changes: Summer 2026

by Victor Grenu

Victor runs IAMTrail, which archives every version of every AWS managed policy, and this is his Summer (not here it wasn't 🥶) diff. There were 248 new policy versions, 93 new policies and 1,022 IAM actions that had never appeared in a managed policy before, about twice last summer's numbers. Several of the 15 new service prefixes are for AI agents, like finops-agent and agent-registry, and new prefixes usually show up in IAM before the docs. ReadOnlyAccess got five new versions in four months, and one of them added agent-registry:InvokeRegistryMcp, which is an odd thing to call read-only. And the SageMaker Studio permissive execution policies picked up events:* and elasticmapreduce:* on every resource, so a data scientist whose role uses one of them can now manage any EventBridge rule or EMR cluster in the account.

From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies

by Margaret Kelley

When AWS finds one of your access keys in a public GitHub repo, it attaches a managed policy called AWSCompromisedKeyQuarantine to the user. Margaret went through every version since 2020, and she links the additions to attacks that may have prompted them, like cryptomining through new Lambda functions, S3 deletions for extortion, and, in October 2024, Bedrock InvokeModel after LLMjacking took off. She also leaked a key on purpose. The policy was attached 10 seconds after the push, which is fast. CloudTrail records the leaked user attaching the policy to itself, with nothing to say AWS did it. And it is still a deny list, not a disabled key, so anything AWS hasn't thought of yet keeps working. Maish Saidel-Keesing, Pawel Rzepa, Nathaniel Quist and William Gamazo, Michael Clark and Bleon Proko have all dug into how AWS handles leaked keys.

🥗 AWS security blogs

🍛 Reddit threads on r/aws


🤖 Dessert

Every machine-tracked change this week. Nobody else assembles this.

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

☕ CloudFormation resource changes

🎮 Amazon Linux vulnerabilities

📺 AWS security bulletins

🚬 Security documentation changes

No changes this week.

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.