Introduction
Read enough cloud incident reports and a pattern emerges. There is rarely a zero-day. There is a public bucket, a key that should not have been in it, and a role with more permissions than anyone remembered granting.
How it works
The chain usually runs: something is readable without authentication, it contains a credential, that credential belongs to an identity with broad permissions, and those permissions reach data that matters.
Each link passed review on its own. The bucket was "only" static assets. The key was "only" for a dev environment. The role was "temporarily" broad. Reviewing findings individually is exactly how the chain survives.
Common risks
A single over-permissive role can convert a minor exposure into a full data breach. Long-lived static credentials make the window indefinite. Missing logging means you cannot answer what was taken.
How to detect it
Enumerate what is publicly reachable from outside your own accounts. Search storage and repositories for credential patterns. Map which identities can assume which roles, and look for paths that end somewhere sensitive.
How to defend
Default deny on storage. Short-lived credentials over static keys. Scope roles to the minimum and review them on a schedule. Enable logging everywhere before you need it. Scan for secrets in code and storage continuously.