{"id":81810,"date":"2026-09-11T18:25:36","date_gmt":"2026-09-11T12:55:36","guid":{"rendered":"https:\/\/www.tothenew.com\/blog\/?p=81810"},"modified":"2026-09-15T16:20:23","modified_gmt":"2026-09-15T10:50:23","slug":"aws-security-misconfigurations-small-drift-severe-blast-radius","status":"publish","type":"post","link":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/","title":{"rendered":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius"},"content":{"rendered":"<p>Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to <em>0.0.0.0\/0<\/em>.<\/p>\n<p>AWS operates on a shared responsibility model. AWS secures the physical infrastructure, virtualization layer, and managed services. You own identity management, network boundaries, data protection, and operational hygiene.<\/p>\n<p>That distinction is important. AWS can provide highly secure building blocks, but an incorrectly configured building block can still create a significant security gap.<\/p>\n<p>The good news is that most of these issues are preventable.<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li><strong>Excessive IAM Privileges &amp; Wildcard Policies<\/strong><br \/>\nIAM is often the first place where convenience wins over security.<br \/>\nThe path of least resistance during development is attaching managed policies such as AdministratorAccess or writing policies containing:<br \/>\n<code><br \/>\n{<br \/>\n\"Effect\": \"Allow\",<br \/>\n\"Action\": \"*\",<br \/>\n\"Resource\": \"*\"<br \/>\n}<br \/>\n<\/code><br \/>\nThis effectively breaks the Principle of Least Privilege (PoLP).The problem becomes much more serious when an application has excessive permissions. For example, an SSRF vulnerability could potentially allow an attacker to access temporary credentials from an instance metadata service. If those credentials have broad permissions, a relatively small application vulnerability can become a much larger AWS compromise.<br \/>\n<strong>Antipattern: Excessive blast radius<\/strong><br \/>\n<code><br \/>\n{<br \/>\n\"Effect\": \"Allow\",<br \/>\n\"Action\": \"s3:*\",<br \/>\n\"Resource\": \"*\"<br \/>\n}<br \/>\n<\/code><strong>Hardened approach<\/strong><br \/>\n<code><br \/>\n{<br \/>\n\"Effect\": \"Allow\",<br \/>\n\"Action\": [<br \/>\n\"s3:GetObject\",<br \/>\n\"s3:PutObject\"<br \/>\n],<br \/>\n\"Resource\": \"arn:aws:s3:::app-production-assets-2026\/*\"<br \/>\n}<br \/>\n<\/code><br \/>\nThe second policy gives the workload only the permissions it actually needs.<strong>Practical controls<\/strong><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><strong>Use targeted resource ARNs.<\/strong><br \/>\nInstead of allowing access to every S3 bucket, restrict permissions to the specific bucket, prefix, queue, table, or secret required by the application.<\/li>\n<li><strong>Use condition keys.<\/strong><br \/>\nConditions such as aws:PrincipalOrgID, aws:RequestedRegion, source VPC endpoints, or encryption requirements can add another layer of control.<\/li>\n<li><strong>Use Permission Boundaries.<\/strong><br \/>\nPermission boundaries establish the maximum permissions an IAM principal can receive, even if someone attempts to attach a broader policy.<\/li>\n<li><strong>Use SCPs for organization-level guardrails.<\/strong><br \/>\nService Control Policies can prevent member accounts from performing certain actions, regardless of permissions granted within the account.<\/li>\n<li><strong>Prefer IAM roles over long-lived access keys.<\/strong><br \/>\nFor EC2, ECS, Lambda, and other AWS workloads, use IAM roles and temporary credentials wherever possible.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The objective isn&#8217;t to eliminate administrative access completely. It is to control where administrative access exists and reduce the blast radius when credentials or workloads are compromised.<\/li>\n<li><strong>Unrestricted Management Ports in Security Groups<\/strong><br \/>\nSecurity Groups are another common source of accidental exposure.Opening SSH or RDP directly to the internet makes infrastructure continuously reachable by external scanners and attackers.<br \/>\n<strong>Antipattern<\/strong><br \/>\n<code><br \/>\nType:     SSH<br \/>\nProtocol: TCP<br \/>\nPort:     22<br \/>\nSource:   0.0.0.0\/0<br \/>\n<\/code><br \/>\nSimilarly:<br \/>\n<code><br \/>\nType:     RDP<br \/>\nProtocol: TCP<br \/>\nPort:     3389<br \/>\nSource:   0.0.0.0\/0<br \/>\n<\/code><br \/>\nThis doesn&#8217;t automatically mean the server is compromised. However, it unnecessarily increases the attack surface and exposes authentication endpoints to brute-force attempts and credential attacks.<strong>Better approach: eliminate direct management ingress<\/strong><br \/>\nFor supported workloads, use AWS Systems Manager Session Manager instead of exposing SSH or RDP.<br \/>\nConceptually:<br \/>\n<code><br \/>\nAdministrator<br \/>\n|<br \/>\n\u2193<br \/>\nSSM Session Manager<br \/>\n|<br \/>\n\u2193<br \/>\nEncrypted HTTPS \/ TCP 443<br \/>\n|<br \/>\n\u2193<br \/>\nEC2 Instance<br \/>\n<\/code><br \/>\nThe instance doesn&#8217;t need an inbound SSH rule for Session Manager access.<br \/>\nFor instances in private or isolated subnets, VPC Interface Endpoints can provide private connectivity to the Systems Manager control plane, including endpoints such as:<br \/>\n<code><br \/>\nssm<br \/>\nssmmessages<br \/>\nec2messages<br \/>\n<\/code><br \/>\n<strong>If SSH\/RDP is genuinely required<\/strong><br \/>\nDon&#8217;t automatically open it to the world. Restrict the source to a trusted network, VPN, bastion host, or specific administrative IP range:<br \/>\nSSH \/ TCP \/ 22<br \/>\nSource: 10.0.36.246\/32<br \/>\nA useful rule is:<\/p>\n<blockquote><p>If an administrative port doesn&#8217;t need to be publicly reachable, don&#8217;t make it publicly reachable.<\/p><\/blockquote>\n<\/li>\n<li><strong>Publicly Exposed Data Stores<\/strong><br \/>\nData stores deserve particular attention because they often contain the information an attacker is ultimately trying to access.The most common mistake is treating &#8220;publicly accessible&#8221; as equivalent to &#8220;compromised.&#8221;It isn&#8217;t.A public database may still have strong authentication and restrictive security groups. However, making it publicly reachable increases the attack surface and creates additional opportunities for misconfiguration.<strong>Amazon S3<\/strong><br \/>\nS3 exposure can occur through:<\/p>\n<ul>\n<li>Bucket policies<\/li>\n<li>IAM policies<\/li>\n<li>Access Control Lists<\/li>\n<li>Account-level settings<\/li>\n<li>Bucket-level settings<\/li>\n<li>Cross-account permissions<\/li>\n<\/ul>\n<p>For buckets that should remain private, enable and regularly validate S3 Block Public Access at the appropriate account and bucket levels.<\/p>\n<p>But don&#8217;t stop at the S3 console&#8217;s public-access indicator.<\/p>\n<p>Think about the complete access path:<br \/>\n<code><br \/>\nUser \/ Workload<br \/>\n|<br \/>\n\u2193<br \/>\nIAM Policy<br \/>\n|<br \/>\n\u2193<br \/>\nBucket Policy<br \/>\n|<br \/>\n\u2193<br \/>\nS3 Object<br \/>\n<\/code><br \/>\nA secure bucket requires the entire authorization chain to be intentional.<\/p>\n<p>Also consider whether sensitive data is encrypted using an appropriate mechanism such as SSE-KMS, and whether access logging and monitoring are configured according to the workload&#8217;s requirements.<\/p>\n<p><strong>Amazon RDS<\/strong><br \/>\nMaking an RDS database publicly accessible does not automatically mean the database has been compromised.<\/p>\n<p>It does, however, increase exposure.<\/p>\n<p>A typical production architecture should look more like:<br \/>\n<code><br \/>\nInternet<br \/>\n|<br \/>\n\u2193<br \/>\nLoad Balancer<br \/>\n|<br \/>\n\u2193<br \/>\nApplication<br \/>\n|<br \/>\n\u2193<br \/>\nPrivate RDS<br \/>\n<\/code><br \/>\nThe database Security Group should allow database traffic only from the application layer that requires it.<br \/>\nFor example:<br \/>\n<code><br \/>\nApplication SG<br \/>\n|<br \/>\n\u2193<br \/>\nTCP 5432<br \/>\n|<br \/>\n\u2193<br \/>\nRDS PostgreSQL<br \/>\n<\/code><br \/>\nrather than:<br \/>\n<code><br \/>\n0.0.0.0\/0<br \/>\n|<br \/>\n\u2193<br \/>\nTCP 5432<br \/>\n|<br \/>\n\u2193<br \/>\nRDS<br \/>\n<\/code><br \/>\nNetwork placement, Security Groups, authentication, encryption, and database configuration should all work together.<\/p>\n<p><strong>Amazon OpenSearch<\/strong><br \/>\nOpenSearch domains also require careful network and access design.<\/p>\n<p>An unnecessarily internet-accessible domain increases the potential attack surface, particularly when combined with weak access policies or authentication controls.<\/p>\n<p>Where appropriate, place OpenSearch within a VPC and restrict access through Security Groups and identity-based controls.<br \/>\nThe general principle is simple:<\/p>\n<blockquote><p>If a data store does not need to be publicly reachable, don&#8217;t expose it.<\/p><\/blockquote>\n<\/li>\n<li><strong>Configuration Drift: The Silent Security Problem<\/strong><br \/>\nOne of the biggest challenges in cloud security is that an environment can start secure and become insecure later.Consider this sequence:<br \/>\n<code><br \/>\nDay 1<br \/>\nSecure configuration<br \/>\n\u2193<br \/>\nDay 30<br \/>\nTemporary firewall rule<br \/>\n\u2193<br \/>\nDay 60<br \/>\nNew IAM permission<br \/>\n\u2193<br \/>\nDay 90<br \/>\nUnused access remains<br \/>\n\u2193<br \/>\nDay 180<br \/>\nSecurity exposure<br \/>\n<\/code><br \/>\nThis is configuration drift.The dangerous part is that nothing necessarily &#8220;breaks.&#8221; Applications may continue working normally while security boundaries slowly deteriorate.<strong>How to control drift<\/strong>Use automated controls rather than relying exclusively on manual reviews.Useful AWS capabilities include:<\/p>\n<ul>\n<li>AWS Config for tracking configuration changes and compliance<\/li>\n<li>AWS Security Hub for centralized security findings<\/li>\n<li>Amazon GuardDuty for threat detection<\/li>\n<li>AWS CloudTrail for API activity and audit trails<\/li>\n<li>AWS IAM Access Analyzer for identifying unintended access<\/li>\n<li>Automated remediation through EventBridge\/Lambda where appropriate<\/li>\n<\/ul>\n<p>For example, AWS Config can detect when a Security Group changes from:<br \/>\n<code><br \/>\nTCP 22 \u2192 10.0.0.0\/8<br \/>\n<\/code><br \/>\nto:<br \/>\n<code><br \/>\nTCP 22 \u2192 0.0.0.0\/0<br \/>\n<\/code><br \/>\nCloudTrail can then help answer the next question:<\/p>\n<blockquote><p>Who or what made the change?<\/p><\/blockquote>\n<p>That distinction is important. Configuration monitoring tells you what changed; audit logs can help determine who made the change and when.<\/li>\n<li><strong><strong>Don&#8217;t Confuse &#8220;Working&#8221; With &#8220;Secure&#8221;<br \/>\n<\/strong><\/strong>A common operational mistake is prioritizing availability over security without revisiting the temporary decision.For example:&#8221;The deployment was failing, so we temporarily gave the role s3:*.&#8221;<br \/>\nOr:&#8221;The developer needed database access, so we temporarily made RDS public.&#8221;<br \/>\nOr:&#8221;We opened port 22 for troubleshooting and will close it later.&#8221;<br \/>\nThe problem isn&#8217;t necessarily the emergency action.The problem is when the temporary exception becomes permanent infrastructure.<\/p>\n<p>Every temporary security exception should have:<\/p>\n<ol>\n<li>An owner<\/li>\n<li>A documented reason<\/li>\n<li>A defined expiration\/review date<\/li>\n<li>Monitoring<\/li>\n<li>A plan to remove it<\/li>\n<\/ol>\n<p>This turns emergency access from an uncontrolled risk into a managed exception.<\/li>\n<\/ol>\n<p><strong>Conclusion<\/strong><br \/>\nAWS security is not only about protecting against sophisticated attacks; it is equally about preventing everyday configuration mistakes from becoming security incidents. Excessive IAM permissions, unrestricted management ports, publicly accessible data stores, and configuration drift can significantly increase an organization&#8217;s attack surface and impact the potential blast radius of a compromise.<\/p>\n<p>A secure AWS environment requires a defense-in-depth approach: apply least-privilege access, restrict network exposure, keep sensitive workloads private, encrypt and protect data, and continuously monitor the environment for unexpected changes.<\/p>\n<p>Ultimately, security should be treated as an ongoing operational practice rather than a one-time configuration task. Regular reviews, automated monitoring, and timely remediation help ensure that AWS environments remain aligned with their intended security posture as infrastructure and applications evolve.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates [&hellip;]<\/p>\n","protected":false},"author":2252,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[5877],"tags":[248,7041],"class_list":["post-81810","post","type-post","status-publish","format-standard","hentry","category-msp","tag-aws","tag-security"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Sejal Verma\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"TO THE NEW BLOG\" \/>\n\t\t<meta property=\"og:type\" content=\"blog\" \/>\n\t\t<meta property=\"og:title\" content=\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@tothenew\" \/>\n\t\t<meta name=\"twitter:title\" content=\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#article\",\"name\":\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog\",\"headline\":\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius\",\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/sejal-verma\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"},\"datePublished\":\"2026-09-11T18:25:36+05:30\",\"dateModified\":\"2026-09-15T16:20:23+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#webpage\"},\"articleSection\":\"MSP, aws, Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/msp\\\/#listItem\",\"name\":\"MSP\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/msp\\\/#listItem\",\"position\":2,\"name\":\"MSP\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/msp\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#listItem\",\"name\":\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#listItem\",\"position\":3,\"name\":\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/msp\\\/#listItem\",\"name\":\"MSP\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\",\"name\":\"TO THE NEW Blog\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/sejal-verma\\\/#author\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/sejal-verma\\\/\",\"name\":\"Sejal Verma\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#authorImage\",\"url\":\"https:\\\/\\\/newersworld-sf-static.tothenew.net\\\/prod\\\/profilePicFolder\\\/b836b226-472c-4df2-9e16-3f0be3c2cb60_Sejal-Verma-Profile-Pitcure.jpeg\",\"width\":96,\"height\":96,\"caption\":\"Sejal Verma\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#webpage\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/\",\"name\":\"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog\",\"description\":\"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\\\/0. AWS operates\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/aws-security-misconfigurations-small-drift-severe-blast-radius\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/sejal-verma\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/sejal-verma\\\/#author\"},\"datePublished\":\"2026-09-11T18:25:36+05:30\",\"dateModified\":\"2026-09-15T16:20:23+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\",\"name\":\"TO THE NEW Blog\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog","description":"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates","canonical_url":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#article","name":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog","headline":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius","author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/sejal-verma\/#author"},"publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"},"datePublished":"2026-09-11T18:25:36+05:30","dateModified":"2026-09-15T16:20:23+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#webpage"},"isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#webpage"},"articleSection":"MSP, aws, Security"},{"@type":"BreadcrumbList","@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.tothenew.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/msp\/#listItem","name":"MSP"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/msp\/#listItem","position":2,"name":"MSP","item":"https:\/\/www.tothenew.com\/blog\/category\/msp\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#listItem","name":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#listItem","position":3,"name":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius","previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/msp\/#listItem","name":"MSP"}}]},{"@type":"Organization","@id":"https:\/\/www.tothenew.com\/blog\/#organization","name":"TO THE NEW Blog","url":"https:\/\/www.tothenew.com\/blog\/"},{"@type":"Person","@id":"https:\/\/www.tothenew.com\/blog\/author\/sejal-verma\/#author","url":"https:\/\/www.tothenew.com\/blog\/author\/sejal-verma\/","name":"Sejal Verma","image":{"@type":"ImageObject","@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#authorImage","url":"https:\/\/newersworld-sf-static.tothenew.net\/prod\/profilePicFolder\/b836b226-472c-4df2-9e16-3f0be3c2cb60_Sejal-Verma-Profile-Pitcure.jpeg","width":96,"height":96,"caption":"Sejal Verma"}},{"@type":"WebPage","@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#webpage","url":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/","name":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog","description":"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/#breadcrumblist"},"author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/sejal-verma\/#author"},"creator":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/sejal-verma\/#author"},"datePublished":"2026-09-11T18:25:36+05:30","dateModified":"2026-09-15T16:20:23+05:30"},{"@type":"WebSite","@id":"https:\/\/www.tothenew.com\/blog\/#website","url":"https:\/\/www.tothenew.com\/blog\/","name":"TO THE NEW Blog","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"TO THE NEW BLOG","og:type":"blog","og:title":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog","og:description":"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates","og:url":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/","og:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","og:image:secure_url":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","twitter:card":"summary","twitter:site":"@tothenew","twitter:title":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius | TO THE NEW Blog","twitter:description":"Security incidents in AWS rarely stem from zero-day exploits against the hypervisor. In practice, they trace back to routine configuration drift: an IAM policy wildcard added at 2 AM to fix a broken deployment, a database spun up in a public subnet for staging, or a security group rule left open to 0.0.0.0\/0. AWS operates","twitter:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png"},"aioseo_meta_data":{"post_id":"81810","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"created":"2026-09-10 14:04:27","updated":"2026-09-15 10:50:25","focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"breadcrumb_settings":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\/category\/msp\/\" title=\"MSP\">MSP<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAWS Security Misconfigurations: Small Drift, Severe Blast Radius\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.tothenew.com\/blog"},{"label":"MSP","link":"https:\/\/www.tothenew.com\/blog\/category\/msp\/"},{"label":"AWS Security Misconfigurations: Small Drift, Severe Blast Radius","link":"https:\/\/www.tothenew.com\/blog\/aws-security-misconfigurations-small-drift-severe-blast-radius\/"}],"_links":{"self":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/81810","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/users\/2252"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/comments?post=81810"}],"version-history":[{"count":8,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/81810\/revisions"}],"predecessor-version":[{"id":83474,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/81810\/revisions\/83474"}],"wp:attachment":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/media?parent=81810"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/categories?post=81810"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/tags?post=81810"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}