Daily Edition
Cyber Security · Saturday, September 12, 2026 · 7 sources

AWS patched CloudTrail logging bypass exposing IAM reconnaissance

Datadog Security Labs discovered an undocumented AWS API, iamadmin, that allowed attackers to call 13 IAM methods without leaving CloudTrail event logs. AWS fixed the flaw in October 2022. For European enterprises relying on CloudTrail for detection, the gap meant stealthy reconnaissance on users, groups, and MFA status.

Bottom line — AWS fixed a logging bypass allowing 13 IAM methods to go unrecorded, per Datadog researcher Nick Frichette.

Go deeper (4)

  • The vulnerability affected CloudTrail, AWS's audit logging service, and could also bypass GuardDuty detection since GuardDuty uses CloudTrail as a data source, per Datadog.
  • Attackers could enumerate IAM groups, policies, and MFA devices without being logged, using the undocumented iamadmin API, Frichette told The Daily Swig.
  • AWS acknowledged the report on March 10, 2022, but the patch required complex internal changes and was only deployed on October 24, 2022, per Datadog and AWS.
  • AWS stated that affected API methods have been modified and no customer action is needed, but the incident highlights the risk of blind spots in cloud logging.

Read the reporting

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Sep 12, 9:06 AM UTC by wreetco wreetco

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Sep 12, 9:06 AM UTC by wreetco wreetco