#IAM
AWS Integration Lambda Could Turn Limited IAM Access Into Privileged Cloud Actions
CVE-2026-94384 allowed callers of an Amazon Connect Salesforce setup function to make AWS requests with the Lambda execution role's privileges. AWS has fixed the issue in AmazonConnectSalesforceLambda 5.26...
Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace
A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...