Amazon patches two AWS flaws discovered by Orca Security that could have exposed information managed by Glue users and leaked sensitive files via CloudFormation
Nathaniel Mott / PCMag :
Context & Ripple Effects
This is another entry in a long line of externally discovered data-exposure risks on AWS: after S3 added default encryption and unencrypted-file warnings in 2017 and researchers found hundreds of exposed EBS snapshots leaking customer credentials and VPN configs in 2019, security firm Orca Security has now surfaced two more flaws — one in Glue that could expose information users manage there, and one in CloudFormation that could leak sensitive files — with Amazon shipping patches for both.
The disclosure also extends Orca's multi-cloud research franchise: months later the same firm would publicly criticize Microsoft for taking several months and three patches to fix a critical Azure vulnerability (per Ars Technica), making patch responsiveness itself part of the competitive story between AWS and Azure.
First-order effects
- AWS customers using Glue and CloudFormation are the direct beneficiaries — the patched flaws closed paths to exposed user-managed information and leaked sensitive files, so applying the fixes removes an active exposure window.
- Orca Security gains disclosed findings on the market-leading cloud, reinforcing its position as a researcher whose reports reach both AWS and Azure customers.
Second-order effects
- The finding keeps pressure on rival hyperscalers' own managed services: with Orca already framing Microsoft's slow Azure patching as a customer risk, patch turnaround becomes a comparable metric across AWS, Azure, and Google's platforms — which had their own DNS-as-a-Service bug exposing internal networks in 2021.
- It reinforces the shared-responsibility friction AWS articulated back when it urged customers to patch their own EC2 instances: every new flaw in a managed service shifts more of the security burden visibly onto the provider, raising expectations for default-safe configurations.
Third-order effects
- If researcher-found exposures in managed services keep recurring, the durable fix is structural rather than per-patch: tighter permission boundaries and encryption-by-default across control-plane services like Glue and CloudFormation, extending the direction S3 took in 2017.
- Independent security firms become de facto auditors of cloud trust — their disclosure cadence and the vendors' response times shape enterprise cloud selection as much as feature roadmaps do.
The trend: Cloud security is shifting toward a model where third-party researchers surface flaws in managed services and each provider's patch speed becomes a competitive differentiator.