Welcome to our

Cyber Security News Aggregator

.

Cyber Tzar

provide a

cyber security risk management

platform; including automated penetration tests and risk assesments culminating in a "cyber risk score" out of 1,000, just like a credit score.

Shadow Roles: AWS Defaults Can Open the Door to Service Takeover

published on 2025-04-29 16:27:21 UTC by /u/Pale_Fly_2673
Content:

TL;DR: We discovered that AWS services like SageMaker, Glue, and EMR generate default IAM roles with overly broad permissions—including full access to all S3 buckets. These default roles can be exploited to escalate privileges, pivot between services, and even take over entire AWS accounts. For example, importing a malicious Hugging Face model into SageMaker can trigger code execution that compromises other AWS services. Similarly, a user with access only to the Glue service could escalate privileges and gain full administrative control. AWS has made fixes and notified users, but many environments remain exposed because these roles still exist—and many open-source projects continue to create similarly risky default roles.

submitted by /u/Pale_Fly_2673
[link] [comments]
Article: Shadow Roles: AWS Defaults Can Open the Door to Service Takeover - published 6 months ago.

https://www.reddit.com/r/netsec/comments/1kas6ia/shadow_roles_aws_defaults_can_open_the_door_to/   
Published: 2025 04 29 16:27:21
Received: 2025 04 29 16:37:20
Feed: /r/netsec - Information Security News and Discussion
Source: /r/netsec - Information Security News and Discussion
Category: Cyber Security
Topic: Cyber Security
Views: 19

Custom HTML Block

Click to Open Code Editor