Close Menu
TechurzTechurz
    What's Hot

    Mark Wahlberg is coming to Disrupt 2026

    September 10, 2026

    Maven Robotics wants to steal your robot deployment deal

    September 10, 2026

    India’s Pocket FM doubles revenue run rate to $500M as AI powers 93% of audio content

    September 10, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Mark Wahlberg is coming to Disrupt 2026
    • Maven Robotics wants to steal your robot deployment deal
    • India’s Pocket FM doubles revenue run rate to $500M as AI powers 93% of audio content
    • Bending Spoons to buy collaboration tools maker Miro for $1.36B, 90% less than its 2022 valuation
    • Google signs its biggest rice-methane carbon credit deal with Indian startup Mitti Labs
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - ECScape: New AWS ECS flaw lets containers hijack IAM roles without breaking out
    Security

    ECScape: New AWS ECS flaw lets containers hijack IAM roles without breaking out

    TechurzBy TechurzAugust 8, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    AWS logo on wall
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Haziz originally set out to build an eBPF-based real-time monitoring tool for ECS workloads. While doing so, he intercepted communication between the ECS agent and AWS backend as part of his debugging process, which is when he noticed the undocumented WebSocket channel.

    From lowly tasks to privileged IAM roles

    Thanks to the default availability of IMDS, any container (with low-level access) on an EC2-based ECS instance can read the instance role credentials intended for the ECS agent.

    β€œNo container breakout (no hostroot access) was required – however IMDS access was required via clever network and system trickery from within the container’s own namespace,” Haziz noted, adding that accessing IMDS lets any container impersonate an ECS agent. AWS has documentation on how to prevent or limit access to IMDS.

    Armed with those instance role credentials, the attacker can forge communication over the ACS WebSocket. This allows them to intercept or request IAM credentials of other running tasks, even if those tasks are supposed to be isolated by IAM roles. Essentially, the compromised container escalates by masquerading as the orchestrator ECS agent responsible for managing and orchestrating tasks.

    β€œThe stolen keys (IAM credentials) work exactly like the real task’s keys,” Haziz said. β€œAWS CloudTrail will attribute API calls to the victim task’s role, so initial detection is tough – it appears as if the victim task is performing the actions.” This lets attackers be invisible in the logs because AWS thinks the victim is doing everything.

    AWS Breaking containers ECS ECScape flaw hijack IAM lets roles
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHerman Miller’s surprise sale slashes prices by 25% – and these are the office chair deals I’d buy for your home and office
    Next Article Stargate’s slow start reveals the real bottlenecks in scaling AI infrastructure
    Techurz
    • Website

    Related Posts

    Opinion

    Robinhood to list a fund that lets anyone back Y Combinator startups

    August 5, 2026
    Opinion

    AWS is helping vibe-coding startup Superblocks, and the implications are big

    August 3, 2026
    Opinion

    Why these startup CEOs don’t think AI will replace human roles

    February 19, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,291

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.