{
  "id": 12737076,
  "title": "In the cloud, lateral movement is an API call, not an exploit",
  "url": "https://urgent.news/2026/10/07/in-the-cloud-lateral-movement-is-an-api-call-not-an-exploit",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T23:35:02.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/rohaan/in-the-cloud-lateral-movement-is-an-api-call-not-an-exploit-4j6c"
  },
  "original_language": "en",
  "account": "Traditional attack paths in network security involve exploiting vulnerabilities, escalating privileges, and pivoting laterally to other systems. However, in cloud environments, the lateral movement process is different. Instead of exploiting vulnerabilities at each step, attackers typically use allowed API calls. The crucial vulnerability often lies in the initial step, such as an SSRF bug that fetches URLs and reveals credentials.\n\nThe trust policies, which define who can assume roles, are crucial but often overlooked. A role with broad permissions and a trust policy that allows any entity in the account to assume it creates significant security weaknesses. Similarly, overly permissive federated trust with loose conditions, such as wildcard subdomains, can grant attackers broad access to assume roles in different environments.\n\nTo effectively secure cloud accounts, it's essential to focus on the trust policies and how they enable lateral movement. Tools like frontdoor, which analyzes trust relationships across AWS, GCP, and Azure, can help visualize the attacker's potential path. By prioritizing the understanding of trust policies and the associated chains of trust relationships, organizations can better protect their cloud environments from lateral movement attacks.",
  "summary": "Most of us learned attack paths on a network. Someone lands on a box, escalates locally, then pivots sideways to the next box. Exploit, escalate, pivot, repeat. It is a good model and it shaped a generation of tooling. In a cloud account it is mostly the wrong model, and the tooling that inherited it keeps looking in the wrong place. The pivot in cloud is usually not an exploit. It is an API call…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}