Issue #281

Monday · October 05, 2026

🥖 Palate Cleanser

Hello again friends,

I don't often mention the other weaker, less attractive clouds but sometimes there is something worth learning from. Haakon Wik Gulbrandsrud found five full cross-tenant compromises in Azure, each one a way into other customers' connected Key Vaults, SQL databases and SaaS backends. It got him $200,000 in bounties, partly by finding ways around Microsoft's fixes for the earlier ones. Fun times.

Three talk videos with AWS content that haven't been in the digest yet:

  • Out of Context: What's Really in the AWS Request Context by Dan Gansel, from fwd:cloudsec Europe. The talk behind last week's top Chef's pick on undocumented IAM condition keys, which I forgot to link. Watch him turn session policies into a yes-or-no oracle for what IAM really sees. Plerion's Conditional Love tool has been updated with the new resource keys Dan found, so you can try them for yourself.
  • What Could Possibly Go Wrong? Running untrusted code in the cloud by Jules Denardou and Daniel Henkel, also from fwd:cloudsec Europe. How to run customer code using separate AWS accounts, S3-scoped VPC endpoint policies and a credentials proxy, and why Lambda didn't make the cut.
  • The Month of AI Bugs: Exploiting AI Computer Use and Coding Agents by Johann Rehberger, from DEF CON Singapore. In August 2025 Johann published a new AI agent bug every day for a month, and this talk covers the worst of them. The AWS bits are two Amazon Q Developer bugs, plus a nod to Kiro having the same config-rewrite flaw.
Sponsor shoutout Plerion

You just read every IAM change AWS shipped this week. The harder question is which of your roles can reach something they shouldn't. Plerion's agents map those attack paths and hand you the fix. See the platform or get a free assessment.

📋 Chef's selections

Package Name to Role Credentials in Code Interpreter: Two RCE CVEs in the AgentCore Python SDK

by Sergio Garcia

AgentCore Code Interpreter is AWS's sandbox where agents run potentially shady code, and its Python SDK has a helper, install_packages(), that lets an agent pip install libraries for you. It yolo-pasted each package name into a shell command, and Sergio got commands past its validation. First with a newline character, then, after the fix, with a command hidden inside pip's extras brackets. If the sandbox is a custom one with an execution role, that command reads the role's credentials from the sandbox's metadata service, so the attacker only needs a way to influence a package name with a prompt injection or a dependency file to get code exec.

Context Bombs Against Abliterated AI Models

by Alessandro Brucato

Context bombs are short strings planted in canaries, decoy resources like fake secrets, that trip a model provider's safety checks when an AI attacker reads them. In July, Sam Cox showed that context bombs took the strongest frontier attack agent from getting admin in 93% of runs to 0%. The original strings did nothing to Qwen, an open-weight model attackers can run on their own hardware, away from any provider's safety checks, so this time Alessandro tried a new payload. He hid a forged chat transcript inside a fake API key in Secrets Manager, ending with the "user" telling the agent its work was done and it should stop. An abliterated build (weights edited to make refusals less likely) replied "Acknowledged, stopping all activities." and quit, and the same trick stopped plain Qwen too. In Tracebit's AWS cyber range the abliterated model reached admin in 2.3% of runs as opposed to 20.5% for the original. The new payload is already in the open-source context-bombs repo.

Read-Only AI Agents on AWS: Two Guardrails Failed in 2026, and IAM Held

by Tatiana Mikhaleva

It's unfortunate this article was (I think) written entirely by AI because it makes a good point, it just requires grinding through slop. Telling AI to only use read-only operations is unlikely to work unless something technical enforces it. Tatiana told an AI agent skill to stay read-only, and it made 25 database writes and reported none. She then did some sleuthing to figure out what keeps an agent read-only on AWS. Turns out it's not the guardrails in AWS's own MCP tools. 😬 In July AWS fixed the AWS API MCP Server, which silently dropped its deny list when an index failed to load, and the MCP proxy, whose --read-only flag hid write tools but still ran them if the agent asked by name.

Bonus: Mapping Scaleway IAM, An Attacker's View of the Trust Boundaries

by Tom De Keyser

🥗 AWS security blogs

🍛 Reddit threads on r/aws


🤖 Dessert

Every machine-tracked change this week. Nobody else assembles this.

🧁 IAM permission changes

🍪 API changes

🍹 IAM managed policy changes

☕ CloudFormation resource changes

No resource updates this week.

📺 AWS security bulletins

🚬 Security documentation changes

🎮 Amazon Linux vulnerabilities

Get every AWS security change,
on a plate every Monday.

6,700+ engineers, builders and CISOs let us diff the AWS changelog every week.