One SCP deny line blocked an AdministratorAccess session in a scratch AWS account, according to a dev.to guide to sandboxing coding agents. Its three gaps, the management account, service-linked roles and outside principals admitted by resource policies, set where an agent can run.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence40
Bala Paranj ran a 2022 AWS privilege-escalation case through a Z3 solver and found its six-action deny policy blocked four of nine compute-launch vectors. Expanding the list to all nine leaves a residual, because each new compute service AWS ships opens a fresh bypass path.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+35
- Incentives
- Insufficient
- Confidence50
AWS lets an S3 presigned URL live up to seven days, and anyone holding a leaked one can use it until it expires or its signer is revoked. Revoking the signer kills every URL it made, so short expiries and a bucket-level cap on signature age are the practical defence.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Truffle Security retested 10,616 publicly leaked AWS credentials and 88 percent still authenticated. The median key was about five years old and had no successor.
Perspective Coverage
5 publishers
- Builder
- Builder 34%
- Operator
- Operator 54%
- Investor
- Investor 12%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives72
- Confidence62
Signing up now takes a Google, GitHub or Apple identity and, for most new customers, no card, with $100 in credits. Each project is a real AWS account carrying a monthly ceiling from $20 that AWS enforces by stopping the work.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives85
- Confidence55
A dev.to account of two AccessDenied failures shows CloudFormation resource providers making supporting calls into adjacent services, so an execution role scoped to the template's service namespaces is incomplete by construction.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+12
- Incentives18
- Confidence45
Permission-by-permission review scores iam:PassRole, lambda:CreateFunction and lambda:InvokeFunction as controlled access, while path analysis sees one route to whatever the passed role holds. Three policy layers decide whether that route is live.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+8
- Incentives50
- Confidence55
A tester gave AWS DevOps Agent a broad elevated role and found its temporary session policy admits only supported actions, while an SSM document that accepts arbitrary package names still installed tmux after one approval.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap−12
- Incentives32
- Confidence44
Unit 42 traced AWSCompromisedKeyQuarantine through three versions since August 2020 and documented the GitHub secret scanning integration that lets AWS attach the policy to an exposed IAM user automatically, with the owner notified afterwards.
Reality
- Evidence62
- Adoption58
- Hype gap+8
- Incentives68
- Confidence55
miruky's console walkthrough puts an order and its outbox event in one DynamoDB transaction, then fails the consumer on purpose to show why redelivery is the consumer's problem. The whole exercise is priced under $5 in us-east-1.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−10
- Incentives22
- Confidence60
The ESP32-S3 example generates the device key on the chip and sends only a CSR to AWS IoT Core. The credential that gets it there is a claim certificate and private key copied into the SPIFFS image every unit shares.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+22
- Incentives30
- Confidence55
A dev.to walkthrough says AWS App Runner no longer accepts new services, and the Amazon ECS Express Mode path it demonstrates opens with an execution role, an infrastructure role, and a public container image.
Reality
- Evidence45
- Adoption12
- Hype gap+25
- Incentives22
- Confidence48
Taking the password out of a Lambda's environment variables costs five console steps and one inline rds-db:connect policy, and buys a database credential that expires fifteen minutes after boto3 mints it.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+26
- Incentives28
- Confidence54
New AWS sign-ups federate to a Google, GitHub or Apple login and arrive as a project whose resource permissions are set by the console and by whatever coding agent the owner pastes AWS's setup text into. The rollout covers new customers only.
Reality
- Evidence55
- Adoption18
- Hype gap+10
- Incentives72
- Confidence52
AWS's landing zone guidance for the European Sovereign Cloud starts at the partition boundary. Credentials in aws-eusc cannot reach resources in aws, so the centralisation an operator already runs gets built a second time inside the new partition.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives78
- Confidence66
Trust Boundary's walkthrough of the 2019 Capital One breach puts the weight on the IAM role attached to the firewall instance, and says the OCC consent order that followed does not mention server-side request forgery at all.
Reality
- Evidence62
- Adoption55
- Hype gap+10
- Incentives35
- Confidence66
IAM Access Analyzer already names the unused permissions and writes the tightened policy. A new AWS pattern sorts each finding by how the role was created and files the fix as a pull request or an issue.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+12
- Incentives65
- Confidence55
AgentCore Identity now hosts the redirect leg and keeps the tokens, and what you configure in exchange is an OIDC application in your corporate IdP, a service role, and AWS's callback URL inside your GitHub and Slack apps.
Reality
- Evidence62
- Adoption12
- Hype gap+8
- Incentives88
- Confidence55
Google's Custom Search JSON API is closed to new customers and stops working on January 1, 2027. One builder replaced it with Amazon Bedrock AgentCore Web Search and paid a 40 percent premium to keep the tool under IAM.
Reality
- Evidence58
- Adoption24
- Hype gap−10
- Incentives45
- Confidence52
Unit 42 committed a fresh, overly permissive AWS key to a random GitHub repository with the usual quarantine policy switched off, then timed how long a cryptojacking crew took to find it and start mining.
Reality
- Evidence52
- Adoption45
- Hype gap+30
- Incentives78
- Confidence60
Earlier coverage
- A poorly scoped supervisor prompt sends 20 percent of requests to the wrong specialist
Build · September 11, 2026 · 1 publisher
- Scoping iam:AttachUserPolicy to the caller's own ARN hands out AdministratorAccess
Build · September 11, 2026 · 1 publisher
- Guardrail policies give one IAM role a different reach in every Slack channel
Build · September 11, 2026 · 1 publisher
- AWS's Quick Automate walkthrough turns a plain-language prompt into an RFI workbook-to-CSV workflow, promoted via Import/Export
Build · September 10, 2026 · 1 publisher
- MLflow now drives lifecycle promotion inside SageMaker's model registry
Build · September 8, 2026 · 1 publisher
- AWS's SIRT traced one SSRF bug to Bedrock calls in a second Region
Build · September 3, 2026 · 1 publisher
- Aurora DSQL's second writable endpoint bills every commit for the inter-Region round trip
Build · September 1, 2026 · 1 publisher
- Jamf enforces per-engineer Bedrock budgets by rewriting an IAM policy every 15 minutes
Build · September 1, 2026 · 1 publisher
- AWS wires Bedrock Guardrails into the hook that fires before a Strands agent calls a tool
Build · August 27, 2026 · 1 publisher
- Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways
Build · August 27, 2026 · 1 publisher
- The open port and the egress bill are one ticket, not two queues
Build · August 23, 2026 · 1 publisher
- GuardDuty says exfiltration and the patch is four hours out: revoke the sessions first
Build · August 23, 2026 · 1 publisher
- Dropping long-lived AWS keys is half an EKS migration; the cluster still gets a vote
Build · August 22, 2026 · 1 publisher
- Bedrock's evaluation modes grade what they can see, and the dataset outlives both
Build · August 22, 2026 · 1 publisher
- CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend
Leadership · August 20, 2026 · 1 publisher
- AWS moves agent authorization out of the agent and into the plumbing
Build · August 19, 2026 · 1 publisher
- Basic Auth becomes a gateway problem: AgentCore's Lambda interceptor keeps the password away from the model
Build · August 18, 2026 · 1 publisher
- Two Actions, One Loose Policy: The Bedrock Wildcards That Widen A Least-Privilege Grant
Build · August 15, 2026 · 1 publisher