Please turn JavaScript on
header-image

Sonrai | Enterprise Cloud Security Platform

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.07 / day

Message History

As February 2026 comes to a close, the focus of AWS permission expansion has moved from core infrastructure to the Generative AI supply chain. This month’s review of newly released permissions highlights a strategic pivot toward model customization and deep-tier telemetry. While the volume of new privileged actions is lower than in January, the impact of thes...


Read full story
Introduction

Following the release of Amazon Bedrock Powered by AWS Mantle, I discovered a mechanism to bypass Service Control Policy (SCP) statements limiting the use of bedrock-mantle IAM permissions. By leveraging long-lived...


Read full story

As January 2026 comes to a close, Sonrai’s latest review of newly released AWS permissions highlights a sharp expansion of privilege concentrated in networking, traffic control, and collaboration services. This month’s updates focus heavily on AWS Network Firewall, Route 53 Global Resolver, EC2 networking controls, and cross-account data collaboration, introducing new ways to...


Read full story
Why I Stopped JIT’ing Users and Started JIT’ing Permissions

By Cole Horsman
Field CTO, Sonrai Security

I first tried to “shift left” cloud identity in early 2020.

We were building a greenfield AWS environment with a strong cloud team and leadership support to do things properly. The idea was familiar...


Read full story

As December 2025 comes to a close, Sonrai’s latest review of newly released AWS permissions highlights a continued expansion of cloud privilege. This month’s updates span identity, observability, AI, and managed service infrastructure, with changes across CloudWatch, CloudFront, Bedrock, EKS, SageMaker, and emerging agent-based platforms.

Together, these permissions...


Read full story