#cloud security
1 published article
Zenity's 8 October AgentCore disclosure traced the blast radius to IAM scope
The researchers' chain depended on an overbroad execution role, not a microVM escape[3][6][8]. AWS says credentials are available inside the runtime and tells customers to scope permissions tightly[6][7].