AWS Built a Security Tool. It Introduced a Security Risk.
(If you missed the previous parts of this trust policy blog series, we recommend reading parts one and two first)In the previous post of this series, we explored four dangerous misconceptions regarding how to securely set up cross-account access in AWS environments.In this final post of the series, we’ll walk through a real-world case where even AWS got it wrong. Their Account Assessment for AWS Organizations tool, designed to audit resource-based policies for risky cross-account access, ironica...
Read more at token.security