Skip to content

framework

AWS IAM

AWS Identity and Access Management (IAM) is Amazon Web Services' service for managing users, roles, and policies controlling access to AWS resources.

Known aliases

  • Amazon Web Services IAM
  • AWS IAM
  • AWS Identity and Access Management
  • AWS Security Token Service
  • AWS STS
  • Customer Managed Policies
  • IAM
  • Identity and Access Management

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

An SCP deny outranks the admin role a coding agent borrows in AWS member accounts

One SCP deny line blocked an AdministratorAccess session in a scratch AWS account, according to a dev.to guide to sandboxing coding agents. Its three gaps, the management account, service-linked roles and outside principals admitted by resource policies, set where an agent can run.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence40
build1 publisher

Revoking one leaked S3 presigned URL takes down every URL its credential signed

AWS lets an S3 presigned URL live up to seven days, and anyone holding a leaked one can use it until it expires or its signer is revoked. Revoking the signer kills every URL it made, so short expiries and a bucket-level cap on signature age are the practical defence.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence50
security5 publishers

Leaked AWS keys keep working: 526 root, 242 admin, and a rotation rate of 13.7 percent

Truffle Security retested 10,616 publicly leaked AWS credentials and 88 percent still authenticated. The median key was about five years old and had no successor.

Perspective Coverage

5 publishers
Builder
Builder 34%
Operator
Operator 54%
Investor
Investor 12%

Reality

Evidence58
Adoption
Insufficient
Hype gap+15
Incentives72
Confidence62

Earlier coverage

  1. A poorly scoped supervisor prompt sends 20 percent of requests to the wrong specialist

    Build · September 11, 2026 · 1 publisher

  2. Scoping iam:AttachUserPolicy to the caller's own ARN hands out AdministratorAccess

    Build · September 11, 2026 · 1 publisher

  3. Guardrail policies give one IAM role a different reach in every Slack channel

    Build · September 11, 2026 · 1 publisher

  4. AWS's Quick Automate walkthrough turns a plain-language prompt into an RFI workbook-to-CSV workflow, promoted via Import/Export

    Build · September 10, 2026 · 1 publisher

  5. MLflow now drives lifecycle promotion inside SageMaker's model registry

    Build · September 8, 2026 · 1 publisher

  6. AWS's SIRT traced one SSRF bug to Bedrock calls in a second Region

    Build · September 3, 2026 · 1 publisher

  7. Aurora DSQL's second writable endpoint bills every commit for the inter-Region round trip

    Build · September 1, 2026 · 1 publisher

  8. Jamf enforces per-engineer Bedrock budgets by rewriting an IAM policy every 15 minutes

    Build · September 1, 2026 · 1 publisher

  9. AWS wires Bedrock Guardrails into the hook that fires before a Strands agent calls a tool

    Build · August 27, 2026 · 1 publisher

  10. Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways

    Build · August 27, 2026 · 1 publisher

  11. The open port and the egress bill are one ticket, not two queues

    Build · August 23, 2026 · 1 publisher

  12. GuardDuty says exfiltration and the patch is four hours out: revoke the sessions first

    Build · August 23, 2026 · 1 publisher

  13. Dropping long-lived AWS keys is half an EKS migration; the cluster still gets a vote

    Build · August 22, 2026 · 1 publisher

  14. Bedrock's evaluation modes grade what they can see, and the dataset outlives both

    Build · August 22, 2026 · 1 publisher

  15. CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend

    Leadership · August 20, 2026 · 1 publisher

  16. AWS moves agent authorization out of the agent and into the plumbing

    Build · August 19, 2026 · 1 publisher

  17. Basic Auth becomes a gateway problem: AgentCore's Lambda interceptor keeps the password away from the model

    Build · August 18, 2026 · 1 publisher

  18. Two Actions, One Loose Policy: The Bedrock Wildcards That Widen A Least-Privilege Grant

    Build · August 15, 2026 · 1 publisher