🕵️ SicherheitslückenCVE-2024-33668 | Zammad up to 6.2.x Upload Cache excessive authentication(17.09.2026 um 02:15 Uhr)
🕵️ SicherheitslückenCVE-2024-33668 | Zammad up to 6.2.x Upload Cache excessive authentication(17.09.2026 um 02:15 Uhr)
🔧 Programmierung 🕛 vor 6 Monaten 7 Min Lesezeit
0

I Gave an AI Agent Access to My AWS Account - Here's What It Found

↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht




I Gave an AI Agent Access to My AWS Account - Here's What It Found






The Moment It Clicked



I asked my AI agent what OS it was running on.



It answered correctly, without me telling it anything.



That's when I stopped thinking of it as a chatbot and started thinking of it as something else entirely: an autonomous operator inside my cloud environment.



The agent is called Om. I built it using an open-source framework called OpenClaw, deployed on an EC2 instance in AWS. Instead of logging into consoles, running CLI commands, or digging through dashboards, I just talk to it. Through Telegram.



This post is a walkthrough of what I tested, what Om did, and more importantly, what it made me think about.






What I Built and How It Works



Before the demo, a quick note on the architecture, because it matters for the security conversation later.







It failed. ❌



Not because it couldn't, but because the IAM role attached to the instance lacked ce:GetCostAndUsage. And instead of hallucinating a cost figure, Om came back with exactly that explanation: here's what's missing, here's the role name, here's how to fix it.



That moment of honest failure is one of the most important things I saw in this entire test. An agent that knows what it doesn't know is far more useful, and far less dangerous, than one that guesses.



I attached ReadOnlyAccess to the role and asked again.





It returned:





  • IAM: 7 custom users and 9 custom roles, filtered from 20+ AWS service-linked roles it correctly excluded.


  • Compute: 1 EC2 instance in ap-south-1, with its root volume, security group, and full VPC topology, subnet, internet gateway, route table.


  • Storage: 1 S3 bucket.



But here's the flag that jumped out: Lambda-specific IAM roles existed in the account with no corresponding Lambda functions in the region.



Om caught that and called it out. Orphaned permissions. A cleanup task. Exactly what a security review would surface, and it appeared without me asking for it.






Test 4: Security Audit - The Real Test



What I asked: "Who created this EC2 instance? When? From where? Treat this as a request from the security team."



|

Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf dev.to lesen.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
1 Quelle
ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability
1 Quelle
ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I Gave an AI Agent Access to My AWS Account - Here's What It Found

Thematisch verwandte Begriffe: Gave, Agent, Access, Account · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...