From a Forgotten S3 Token to Full AWS Root: Anatomy of a Real-World Cloud Takeover
A step-by-step forensic breakdown of an attack chain escalating an unprivileged S3 read token to full AWS organization root control via STS assume-role abuse.

Anatomy of an AWS IAM Escalation: From Stale S3 Key to Root Control
During a recent simulated enterprise adversary engagement, our offensive security engineers gained initial footholds through a forgotten, read-only IAM access key embedded in an abandoned CI/CD pipeline.
Within four hours, this low-privilege read token was escalated into full organization-level root access across seventy AWS accounts. Here is the exact step-by-step forensic breakdown of how the privilege escalation occurred.
Cloud identity is the new enterprise perimeter. In complex multi-account environments, trust relationships between roles are frequently the most vulnerable lateral movement pathways.
The Multi-Step Escalation Chain
Critical Remediation Steps
Every organization running multi-account cloud estates should implement the following guardrails:
More from The Exploit Company

Why Guardrails Fail: The Anatomy of Multi-Turn Context Bleed in Autonomous AI Agents
How incremental benign prompts across long conversation horizons gradually bleed latent state and bypass keyword safety boundaries in reasoning models.

Escaping the MicroVM: How a PCIe DMA Race Condition Collapsed Hypervisor Isolation
A deep dive into CVE-2026-44192, where an asynchronous memory race in virtual device emulation allowed unprivileged guest code to hijack the host kernel.