AWS is rolling out a simplified sign-up experience that lets customers use Google, GitHub, or Apple identities to create a preconfigured project with Free Tier credits and configurable monthly spending limits. The environment is implemented as a restricted three-account AWS Organization sandbox—comprising a user-facing member account plus hidden management and identity accounts—and can pause projects or apply controls that prevent new workload creation after a budget threshold is reached. AWS also automates service permissions through console workflows, coding agents, and IAM Role Manager, reducing the need to create IAM users, trust policies, or service permissions manually.
Security researchers found the sandbox is designed for onboarding and cost control rather than a complete security baseline. It does not enable CloudTrail and blocks GuardDuty, Security Hub, Detective, Inspector, Macie, and IAM Access Analyzer; it can also allow IAM access keys, public S3 buckets after protections are disabled, and EC2 instances using IMDSv1. Generated roles remain visible and modifiable, but may receive broad permissions such as PowerUserAccess where AWS cannot infer required access, requiring review and least-privilege refinement. Organizations needing centralized governance, multiple Regions, or full security-service coverage must enable advanced features and review inherited automated access rules and restrictive sandbox policies.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
Wiz reported that the new AWS sign-up experience provisions a three-account AWS Organization with hidden management and identity accounts and applies SCPs and RCPs to the accessible member account. Its analysis found no configured CloudTrail, blocked access to several security services, and permitted potentially risky configurations such as IAM access keys, public S3 buckets after disabling blocking, and EC2 IMDSv1 after changing defaults.
AWS began a gradual rollout of a simplified onboarding model in which new customers can use Google, GitHub, or Apple identities and receive an automatically created project. The model provides Free Tier credits, configurable spending limits that pause projects when reached, email-based project sharing, and automatic permission configuration through supported workflows and coding agents.
AWS described IAM Role Manager, which can create and attach IAM roles from managed templates during supported service-console workflows. For user-written Lambda code, the feature may attach the broad PowerUserAccess policy and AWS recommends later least-privilege refinement using IAM Access Analyzer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
wiz.io
Open sourcehelpnetsecurity.com
Open sourceaws.amazon.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.