Issue #280
Monday · September 28, 2026
🥖 Palate Cleanser
I've been hassling you for months now. This is your last chance to nominate research for the AWS Security Digest Top 10. Nominations close this Wednesday, 30 September. Results will be announced on 28 October, and I'm going to convince Eduard to send Milo to the winners.
The fwd:cloudsec Europe individual talk videos went live on Thursday and the whole playlist is worth a scroll. The list includes these AWS-related presentations:
- Complicated Conditions: Enforcing IP-based IAM Restrictions in AWS at Scale by Luke Young. What broke when he put IP restrictions on 100,000 roles.
- Whose Fault When a Pentest Agent Attacks the Wrong Target? by Richard Fan. AWS Security Agent follows a redirect out of scope, starts a pentest of amazon.com after a DNS swap, and runs a planted C2 client that gives him root on its runtime.
- Short-Lived Tokens, Permanent Access: OIDC Roles at Risk by Hila Ramati. A real breach where a GitHub Actions role rewrote its own trust policy to trust the attacker's org, plus data showing 93% of AWS environments have at least one OIDC role that accepts any branch.
- Lessons from benchmarking AI attackers in AWS by Alessandro Brucato. The better the model, the more canaries it trips, because it enumerates harder.
- Paying the CAP Price by Eduard Agavriloae. The notyet research on IAM eventual consistency, now with cross-region timings from his SQS tests.
- Preventing Confused AI Deputies in Multitenant AWS Applications by Rich Mogull. A reference architecture that keeps AI calls inside one tenant's data.
- The Identity Debt (Almost) Nobody's Counting by Alex Waddell and Meg Peddada. Non-human identity war stories from two AWS solutions architects.
This issue is also available to share online. Got feedback? Tell us here.
📋 Chef's selections
by Dan Gansel
This is so cool. Every AWS API call carries a request context, a set of facts like the caller's IP that your policy conditions are checked against. AWS documents what's in it, but the list is incomplete. Dan turned session policies into a yes-or-no oracle, threw about 36 million guessed key names at IAM, and found 36 that the engine already evaluates but AWS has never documented. My favourite is aws:ResourceOrgMasterAccountId, which allows enumeration of the management account ID behind a public resource. In theory, you should be able to drop some of these keys into the Conditional Love tool Plerion published a while back.
AWS Managed Policy Changes: Summer 2026
by Victor Grenu
Victor runs IAMTrail, which archives every version of every AWS managed policy, and this is his Summer (not here it wasn't 🥶) diff. There were 248 new policy versions, 93 new policies and 1,022 IAM actions that had never appeared in a managed policy before, about twice last summer's numbers. Several of the 15 new service prefixes are for AI agents, like finops-agent and agent-registry, and new prefixes usually show up in IAM before the docs. ReadOnlyAccess got five new versions in four months, and one of them added agent-registry:InvokeRegistryMcp, which is an odd thing to call read-only. And the SageMaker Studio permissive execution policies picked up events:* and elasticmapreduce:* on every resource, so a data scientist whose role uses one of them can now manage any EventBridge rule or EMR cluster in the account.
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
When AWS finds one of your access keys in a public GitHub repo, it attaches a managed policy called AWSCompromisedKeyQuarantine to the user. Margaret went through every version since 2020, and she links the additions to attacks that may have prompted them, like cryptomining through new Lambda functions, S3 deletions for extortion, and, in October 2024, Bedrock InvokeModel after LLMjacking took off. She also leaked a key on purpose. The policy was attached 10 seconds after the push, which is fast. CloudTrail records the leaked user attaching the policy to itself, with nothing to say AWS did it. And it is still a deny list, not a disabled key, so anything AWS hasn't thought of yet keeps working. Maish Saidel-Keesing, Pawel Rzepa, Nathaniel Quist and William Gamazo, Michael Clark and Bleon Proko have all dug into how AWS handles leaked keys.
💸 Sponsor shoutout
Most code shipped today is AI-generated and the triage queue grew to match. Pleri AI works out which findings are actually exploitable and submits the fix. See the platform and get a free assessment.
🥗 AWS security blogs
- 📢 AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
- 📢 AWS DataSync launches a monitoring dashboard for tracking task executions across your account
- 📢 AWS End User Messaging now supports voice calling on WhatsApp
- 📢 AWS Network Security Manager is now generally available in US East (N. Virginia) Region
- 📢 Amazon ElastiCache Global Datastore now supports tagging and tag-based access control
- 📢 AWS Security Hub AI Inventory adds Azure self-hosted instance support
- 📢 Amazon Connect Customer launches agent-to-agent collaboration
- Standing Up a Governed AWS Foundation in Days, Not Quarters: A Post-Merger Integration Pattern for Financial Services by Abiola Olanrewaju
- Controlling delegation in agentic AI with Amazon Bedrock Agent Core by Brigette Bucke
- ICYMI: August 2026 @AWS Security by Rodolfo Brenes
- Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever by Grace Zhang
- Transforming Bedrock Guardrails events into OCSF with CloudWatch by Dhananjay Karanjkar
🍛 Reddit threads on r/aws
- If you're letting an AI agent run AWS CLI commands, don't trust its own "I'll ask before anything risky" instructions !!
- ssmctl v2: SSM Session Manager without the pain (shell, port forwarding, commands and file copy over SSM)
- AWS account structure for hosting multiple client websites
- Something else than billing, support, SES issues. Post about iam:PassRole
- Building a plugin pipeline in an AgentCore Gateway interceptor: budgets, guardrails, routing and caching, with measurements
- Having some trouble with automating RDS stops using EventBridge+SSM
- AWS Builder ID verification emails not arriving
- So how are you actually using agentic AI for AWS cloud security work ?
- Practical approaches to enforcing AI tenant isolation when everyone wants shared everything
🤖 Dessert
Every machine-tracked change this week. Nobody else assembles this.
🧁 IAM permission changes
🍪 API changes
- ARC
- Agents for Amazon Bedrock
- Amazon Bedrock AgentCore Control
- Amazon Connect Service
- AWS Glue
- AWS MediaConnect
- Amazon Neptune Graph
- Amazon Q Connect
- Amazon Rekognition
- AWS Security Agent
- AWS Well
- Amazon CloudWatch
- Amazon DataZone
- Amazon ElastiCache
- Amazon EventBridgeV2
- Amazon EventBridge
- AWS Marketplace Discovery
- AWS Security Agent
- AWS Billing
- Connect Health
- Amazon Kinesis
- Amazon Lex Model Building V2
- AWS Elemental MediaConvert
- AWS Elemental MediaPackage v2
- AWS Network Security Manager Customer API
- Payment Cryptography Data Plane
- Amazon API Gateway
- CloudWatch Omni
- Amazon Elastic Compute Cloud
- AWS Glue
- CloudWatch Observability Admin Service
- Amazon QuickSight
- AWS Single Sign
- Amazon Bedrock AgentCore Control
- Amazon Bedrock AgentCore
- AWSBillingConductor
- Amazon DocumentDB with MongoDB compatibility
- Amazon SageMaker Service
🍹 IAM managed policy changes
- AmazonECSInfrastructureRoleForGatewayHostSharedALB
- AnthropicReadOnlyAccess
- AnthropicLimitedAccess
- AnthropicFullAccess
- IVSReadOnlyAccess
- AWSServiceRolePolicyForBackupRestoreTesting
- AWSSecurityAgentWebAppPolicy
- AmazonEventBridgeReadOnlyAccess
- AIDevOpsAgentAccessPolicy
- NetworkSecurityDirectorServiceLinkedRolePolicy
- AWSWellArchitectedAgentResourceScanningServiceRolePolicy
- ReadOnlyAccess
- AWSCloudWatchOmniServiceRolePolicy
- FinOpsAgentAgentPolicy
- AWSObservabilityAdminTelemetryEnablementServiceRolePolicy
- AWS_ConfigRole
- AWSConfigServiceRolePolicy
- AWSObservabilityAdminTelemetryEnablementServiceRolePolicy
- SageMakerStudioProjectProvisioningRolePolicy
- AWSTransferServiceRolePolicy
- CloudWatchReadOnlyAccess
- CloudWatchFullAccessV2
- AWSCloudWatchOmniServiceRolePolicy
- CloudWatchOmniAWSIntegrationPolicy
- CloudWatchOmniSpaceAccessPolicy
- CloudWatchOmniModelInferencePolicy
- CloudWatchOmniDomainAccessPolicy
- AWSBillingConductorRolePolicy
- AWSBillingConductorReadOnlyAccess
☕ CloudFormation resource changes
🎮 Amazon Linux vulnerabilities
- CVE-2026-88816: Perl DBI FetchHashKeyName bug fix
- CVE-2026-91765: PHP SOAP parser unbounded recursion DoS
- CVE-2026-91769: PHP OpenSSL streams fall back to CN on SAN mismatch
- CVE-2026-91767: PHP OpenSSL wildcard cert name length underflow
- CVE-2026-17545: PHP on Windows accepts reserved device names in paths
- CVE-2026-6103: PHP phar TAR size field integer overflow
- CVE-2025-1218: PHP mysqlnd over-read from malicious MySQL server
- CVE-2026-76654: containerd Windows NTLM coercion via subPath symlink
- CVE-2026-92842: PHP stream filter line-break option overflow
- CVE-2026-91768: PHP-FPM IPv6 allowed_clients matches a /96, not the host
- CVE-2026-94282: libXi XI2 cookie conversion OOB read
- CVE-2026-91766: PHP HTTP wrapper leaks auth headers on cross-host redirect
- CVE-2026-88815: Perl DBI sql_type_cast bug fix
- CVE-2026-42394: Dovecot Pigeonhole follows symlinks out of user storage
- CVE-2025-14181: PHP SOAP client response buffer overflow
- CVE-2026-93682: PHP HTTP wrapper over-read on empty Location header
- CVE-2026-95622: ModemManager Cell Broadcast parsing crash
- CVE-2026-94422: xdg-dbus-proxy D-Bus message filter bypass
- CVE-2026-96280: Flatpak OCI delta size truncation overflow
- CVE-2026-96543: GIMP PVR loader heap overflow
- CVE-2026-96748: PyMongo connection string host injection
- CVE-2026-88382: hiredis RESP parser memory exhaustion
- CVE-2026-92709: rsyslog dynaFile path traversal
- CVE-2026-88372: libsndfile MAT4 header integer overflow
- CVE-2026-88387: LibRaw TIFF tag parsing bug
- CVE-2026-96279: Flatpak OCI layer extraction path escape
- CVE-2026-88386: libsndfile WAV misaligned read
- CVE-2026-97185: GIMP GIMPressionist preset out-of-bounds write
- CVE-2026-93542: libXi XI2 class parsing OOB read
- CVE-2026-88373: libde265 NULL deref on empty NAL unit
- CVE-2026-88384: OpenEXR NULL deref on zero-size attribute
- CVE-2026-93544: libXi XIQueryDevice OOB read
- CVE-2026-95521: rpm command injection via source RPM file names
- CVE-2026-96283: Flatpak lets users orphan another user's pull
- CVE-2026-93541: libXi XQueryDeviceState OOB read
- CVE-2026-94281: libXi XListInputDevices OOB read
- CVE-2026-96544: GIMP PVR loader integer overflow
- CVE-2026-79680: Qt VNC server auth bypass
- CVE-2026-96749: PyMongo BSON encoder integer overflow
- CVE-2026-93402: rsyslog DTLS input skips permitted peer check
- CVE-2026-93543: libXi XI2 class parser OOB read
- CVE-2026-96281: Flatpak ref removal defeats anti-downgrade check
- CVE-2026-93403: rsyslog mmpstrucdata stack overflow
- CVE-2026-88383: libical parameter parsing function pointer bug
- CVE-2026-96747: PyMongo treats KMS hosts ending .sock as Unix sockets
- CVE-2026-96284: Flatpak system helper file read via OCI symlinks
- CVE-2026-95519: rpm code execution via crafted manifest
- CVE-2026-88359: libfyaml stack exhaustion on large block scalar
- CVE-2026-93545: libXi XListInputDevices OOB read
- CVE-2026-96282: Flatpak extension setup symlink race
- CVE-2026-96276: Flatpak build-init extension path escape
- CVE-2026-77423: JLine less viewer regex DoS
- CVE-2026-86247: Tomcat Native client cert check downgrade race
- CVE-2026-86246: Tomcat Native insecure TLS options on by default
- CVE-2026-95507: QEMU libslirp NC-SI OOB read
- CVE-2026-96545: GIMP TIM loader OOB read
- CVE-2026-77756: Tomcat HTTP/1.0 request smuggling
- CVE-2026-96675: alsa-lib multi PCM plugin DoS
- CVE-2026-96808: Flatpak revokefs path check bypass
- CVE-2026-87022: Tomcat WebSocket message smuggling
- CVE-2026-96674: alsa-lib topology size integer overflow
- CVE-2026-89425: jackson-core error message DoS
- CVE-2026-91777: jackson-databind object ID resolution DoS
- CVE-2026-96807: Flatpak sandboxed app arbitrary file write via .ld.so
- CVE-2026-86248: Tomcat CLIENT_CERT auth fails open
- CVE-2026-96541: gnome-remote-desktop RDP connection DoS
- CVE-2026-78383: Tomcat AJP thread pinning DoS
- CVE-2026-76183: Tomcat WebSocket security constraint bypass (8.2)
- CVE-2026-86350: Tomcat HTTP/2 request smuggling regression
- CVE-2026-78437: Tomcat malformed request fails another user's request
- CVE-2026-86243: Tomcat Native TLS handshake over-read crashes JVM
- CVE-2026-96442: Emacs Flymake runs code from edited files
- CVE-2026-96275: Flatpak malicious repo writes arbitrary host files (8.8)
- CVE-2026-92162: Flatpak OCI remote crafted arch name abuse
- CVE-2026-73581: Tomcat ignores CRLs with keystore certs
- CVE-2026-96889: librsvg XInclude use-after-free
- CVE-2026-79677: Tomcat async request timeout DoS
- CVE-2026-77422: JLine grep regex DoS
- CVE-2026-79616: Qt Quick SVG path OOB read
- CVE-2026-78253: Qt XML reader recursion DoS
- CVE-2026-96512: sudo NOTBEFORE/NOTAFTER timezone bypass
- CVE-2026-59980: Python hpack integer decoding DoS
- CVE-2026-91776: jackson-databind deserializer cache DoS
- CVE-2026-77762: Tomcat HTTP/2 trailer injection race
- CVE-2026-75973: Tomcat Jakarta Authentication cross-app bypass
- CVE-2026-77420: JLine history pattern DoS
- CVE-2026-96546: GIMP DDS loader one-byte OOB read
- CVE-2026-77421: JLine nano regex DoS
- CVE-2026-77791: Tomcat WebSocket close message DoS
- CVE-2026-87079: Perl Net::IDN punycode decode CPU exhaustion
- CVE-2026-63276: LibreOffice CFF to Type 1 stack overflow
- CVE-2026-63279: LibreOffice PICT palette OOB read
- CVE-2026-95503: Keycloak Kerberos provider auth flaw
- CVE-2026-63275: LibreOffice CFF glyph hints stack overflow
- CVE-2026-87081: Perl Net::IDN UTS46 punycode CPU exhaustion
- CVE-2026-94574: wget Windows build hardcoded config path code exec
- CVE-2026-74766: Perl Net::IDN punycode decode use-after-free
- CVE-2026-63273: LibreOffice encrypted PDF import heap overflow
- CVE-2026-95619: libstdc++ operator new integer overflow
- CVE-2026-63272: LibreOffice WMF text record heap overflow
- CVE-2016-15059: Perl Net::IDN punycode encode heap overflow (8.2)
- CVE-2026-95508: QEMU libslirp DHCPv6/TFTP heap overflow
- CVE-2026-90462: SSSD LDAP ppolicy access check fails open
- CVE-2026-87078: Perl Net::IDN punycode memory leak
- CVE-2026-95818: glibc ld.so stack overflow in setuid programs
- CVE-2026-89407: jackson-core number validation regex DoS
- CVE-2026-75432: yaml-cpp scanner info disclosure
- CVE-2026-86805: glibc ld.so TOCTOU race privilege escalation
- CVE-2026-74765: Perl Net::IDN punycode encode OOB read
- CVE-2026-87082: Perl Net::IDN malformed UTF-8 hang or crash (8.2)
- CVE-2026-63278: LibreOffice URLs leak env vars and INI values
- CVE-2026-94640: rpcbind unauthenticated DoS
- CVE-2026-95511: CUPS serial backend privilege escalation (8.2)
- CVE-2026-96269: Emacs code execution on opening a file
- CVE-2026-87080: Perl Net::IDN pure-Perl decoder wrong output
- CVE-2026-85495: pppd pre-auth LCP buffer overflow
- CVE-2026-63274: LibreOffice PDF stream import heap overflow
📺 AWS security bulletins
- CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
- CVE-2026-94450 - Potential denial of service when configured to send Retry packets in s2n-quic
- CVE-2026-95985 - Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces
- CVE-2026-96883 - Type confusion in AWS pgcollection allows remote code execution
🚬 Security documentation changes
No changes this week.