SECURITY Signal 326
AWS quarantine policy leaves hundreds of leaked root keys active, misses RDS, SSM, role assumption
A Truffle Security finding found hundreds of leaked AWS root keys remain active, and AWS's quarantine policy fails to block many dangerous actions like RDS, SSM, and role assumption.
Relying on AWS's quarantine policy after a credential leak is not enough; attackers can still access RDS, run commands on EC2, and assume roles. The deny-list approach misses many operations, so rotating keys and monitoring remain essential. AWS's goal to avoid breaking customer environments leaves gaps that can be exploited.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
AWS's quarantine policy for leaked credentials leaves many dangerous actions unblocked, including RDS, SSM, and sts:AssumeRole.
Hundreds of leaked AWS root keys remain active and valid, according to a Truffle Security finding.
The policy allows actions like s3:PutObject and secretsmanager:GetSecretValue, so attackers can still store data and read secrets.
THE CLUSTER