Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

AWS's quarantine policy may leave leaked root keys dangerously usable

A security analyst argues that AWS’s automated quarantine of compromised root credentials fails to stop attackers from exploiting many services.

Recent reports revealed hundreds of active leaked AWS root keys, leading AWS to automatically enforce a quarantine policy that restricts specific actions. The author contends that the policy’s selective denials still permit attackers to assume roles, run commands on EC2, create auto-scaling groups, modify S3 objects, and disable audit logging, among other capabilities. By exploiting these gaps, a bad actor could fill storage buckets, enforce immutable retention policies, extract secrets, and delete backups or CloudFormation stacks.

The piece highlights that while some high-value operations are blocked, many critical privileges remain open, undermining the intended protection. The writer urges AWS to reconsider its strategy and asks how large an incident must be before changes are made.

Why it matters

AWS customers may still face severe breaches even after quarantine policies are applied.

In this story

AWSroot keysquarantine policycredential leakagecloud securityservice permissionsattack surfacecredential rotationincident response
Get the beta ↗