TGViewer
CloudSec Wine CloudSec Wine @cloud_sec · 2.28K subscribers
Post #1173 482
🔶 CloudTrail Logging Evasion: Where Policy Size Matters

Permiso uncovered a subtle yet critical logging evasion vulnerability within AWS environments - mainly the differing size limitations of individual AWS CloudTrail logs versus the actual content being logged. By exploiting whitespace and other syntactic quirks, an attacker can create valid IAM policies that effectively bypass CloudTrail logging.

https://permiso.io/blog/cloudtrail-logging-evasion-where-policy-size-matters

#aws
  • ❤ 1
  • 👍 1
  • 🔥 1
More from @cloud_sec
  1. Sep 30, 2026🤖 Hacking OpenAI Researchers chained a libheif heap buffer overflow (via Discourse/ImageM…
  2. Sep 29, 2026👩‍💻 How to secure edge AI in customer-owned environments Edge AI shifts trust responsibi…
  3. Sep 28, 2026🤖 Containers Are No Longer a Security Boundary AI-accelerated kernel vuln discovery (5,97…
  4. Sep 25, 2026🔶 Introducing Amazon EBS Volume Clones across AWS account AWS introduces Amazon EBS Volum…
  5. Sep 24, 2026🤖 DeepSeek Harness Vulnerability. Lets AI Agents Escape Their Own Sandbox CVE-2026-82533…
  6. Sep 23, 2026🤖 Hacking AI customer service agents Techniques for attacking AI customer service agents:…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →