CloudFormation is supposed to automate deployments, but what happens when it has more permissions than you do?
Next week, Samanta Aranda shows how attackers abuse misconfigured execution roles, iam:PassRole, and Lambda-backed Custom Resources to escalate privileges and establish persistence in AWS.