ThreatCluster

Hackers Exploit AWS IAM Eventual Consistency for Stealthy Persistence

First seen 10 Dec 2025, 06:46 UTC CybersecuritynewsCyberpress 20

Article Content

Browse articles
ThreatCluster

Hackers are exploiting the eventual consistency of AWS IAM updates to maintain access to compromised accounts. When security teams delete credentials, the changes do not propagate immediately across the AWS infrastructure, allowing attackers to remain undetected. This vulnerability affects organizations relying on AWS for identity and access management.