An Hour Into the Assessment We’re Cloud Admin – and It’s Never a Zero-Day
This piece is my read on research published by Pathfinding Labs. The findings are theirs; the argument about what they mean is mine. Their original write-up is worth reading in full.
Most companies here believe their cloud is secure. Because somebody configured IAM policies. Because there is a CSPM showing green. Because “it’s AWS, they handle security”.
Wake up.
This week I came across a platform called Pathfinding Labs. Someone at Datadog built real practice environments for AWS IAM privilege escalation. Not a slide deck. Not a webinar. Not a theoretical 40-hour course. Real practice, with real credentials, in a real cloud environment.
And you know what is most frightening there? The scenarios. Self-escalation, where an ordinary user becomes admin. Cross-account attacks that let you hop between accounts. Toxic combinations of permissions where each one on its own looks entirely innocent – but together? Full access.
This is exactly what happens in real companies
Somebody granted an IAM role a few permissions that “looked fine”. Nobody checked the chain. Nobody thought one hop, two hops, three hops ahead. Because who has the time. Because “it’s only a dev environment”. Because “we’re a small startup, who would attack us”.
I see this at clients all the time. They come in for a penetration test, and within an hour we have admin over the entire cloud. Not because of a zero-day. Not because of some sophisticated break-in. Because of an IAM policy somebody copied off Stack Overflow two years ago and forgot about.
The real problem is that not enough people understand this. Not IT managers. Not DevOps. Not even some security people.
Because IAM privilege escalation is not a sexy topic. There is no spectacular ransomware in it. No hackers in hoodies in a dark room. There are permission tables, arrows, and JSON files that make you want to cry.
But that is exactly the vector they come in through. Not through the door. Through the permissions.
What to do about it
If you have a DevOps or security team working with AWS, send them to practice. Not a webinar – actual practice. Because in the cloud, anyone who does not understand permissions in depth is simply not secured.
Full stop.
I first shared a version of this as a LinkedIn post on 2026-06-10. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
