Assume the Worst: Enumerating AWS Roles Through ‘AssumeRole’ 8 years ago
I’ve been evaluating AWS and other cloud services and I think their control planes are a really interesting and not well explored area from a security perspective. My guess is we will see many future security incidents that seem like rehashes or old 90s type exploits or user/admin failures due to complexity.