/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Amazon patches two AWS flaws discovered by Orca Security that could have exposed information managed by Glue users and leaked sensitive files via CloudFormation

Nathaniel Mott / PCMag :

PCMag Nathaniel Mott

Context & Ripple Effects

This is another entry in a long line of externally discovered data-exposure risks on AWS: after S3 added default encryption and unencrypted-file warnings in 2017 and researchers found hundreds of exposed EBS snapshots leaking customer credentials and VPN configs in 2019, security firm Orca Security has now surfaced two more flaws — one in Glue that could expose information users manage there, and one in CloudFormation that could leak sensitive files — with Amazon shipping patches for both.

The disclosure also extends Orca's multi-cloud research franchise: months later the same firm would publicly criticize Microsoft for taking several months and three patches to fix a critical Azure vulnerability (per Ars Technica), making patch responsiveness itself part of the competitive story between AWS and Azure.

First-order effects

  • AWS customers using Glue and CloudFormation are the direct beneficiaries — the patched flaws closed paths to exposed user-managed information and leaked sensitive files, so applying the fixes removes an active exposure window.
  • Orca Security gains disclosed findings on the market-leading cloud, reinforcing its position as a researcher whose reports reach both AWS and Azure customers.

Second-order effects

  • The finding keeps pressure on rival hyperscalers' own managed services: with Orca already framing Microsoft's slow Azure patching as a customer risk, patch turnaround becomes a comparable metric across AWS, Azure, and Google's platforms — which had their own DNS-as-a-Service bug exposing internal networks in 2021.
  • It reinforces the shared-responsibility friction AWS articulated back when it urged customers to patch their own EC2 instances: every new flaw in a managed service shifts more of the security burden visibly onto the provider, raising expectations for default-safe configurations.

Third-order effects

  • If researcher-found exposures in managed services keep recurring, the durable fix is structural rather than per-patch: tighter permission boundaries and encryption-by-default across control-plane services like Glue and CloudFormation, extending the direction S3 took in 2017.
  • Independent security firms become de facto auditors of cloud trust — their disclosure cadence and the vendors' response times shape enterprise cloud selection as much as feature roadmaps do.

The trend: Cloud security is shifting toward a model where third-party researchers surface flaws in managed services and each provider's patch speed becomes a competitive differentiator.

Discussion

  • @0xdabbad00 Scott Piper on x
    😱😱😱 This is worse than ChaosDB for AWS. @orcasec gained access to all AWS resources in all AWS accounts! They accessed the AWS internal CloudFormation service. https://orca.security/... Separately, they did something similar for Glue. https://orca.security/... https://twitter.com…
  • @collabjonathan Jonathan Schulenberg on x
    A vulnerability this catastrophic. The skill to find it, and report it. To patch that fast, at that scale. Just stunning. https://twitter.com/...
  • @nonamesecurity @nonamesecurity on x
    New research by Orca Security that identified API Vulnerabilities in the AWS CloudFormation dubbed BreakingFormation. BreakingFormation emphasizes the urgent need for API security. Organizations must be aware of each API in their API inventory. https://nonamesecurity.com/...
  • @j0hnnyxm4s @j0hnnyxm4s on x
    The Cloud is still Somebody Else's Computer, and when a malicious entity can become that Somebody Else, you'll quickly regret allowing Provider Access to your cloud infra. Reconsider this in your threat models. https://orca.security/...
  • @pcmag @pcmag on x
    The flaw could be used by AWS Glue users to access other users' data. A second bug with AWS CloudFormation, also fixed, could have been used to leak sensitive files. https://www.pcmag.com/...