Close Menu
TechurzTechurz
    What's Hot

    OpenAI acquires presentation startup NextSlide

    August 8, 2026

    Today’s the last day to get up to $400 off your TechCrunch Disrupt 2026 ticket

    August 7, 2026

    Host your own piece of Disrupt: Apply to run a Side Event at TechCrunch Disrupt 2026

    August 7, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • OpenAI acquires presentation startup NextSlide
    • Today’s the last day to get up to $400 off your TechCrunch Disrupt 2026 ticket
    • Host your own piece of Disrupt: Apply to run a Side Event at TechCrunch Disrupt 2026
    • The founder’s guide to TechCrunch Disrupt 2026: Everything you need to know
    • Get up to $400 off your TechCrunch Disrupt 2026 pass until tomorrow
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - ECScape: New AWS ECS flaw lets containers hijack IAM roles without breaking out
    Security

    ECScape: New AWS ECS flaw lets containers hijack IAM roles without breaking out

    TechurzBy TechurzAugust 8, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    AWS logo on wall
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Haziz originally set out to build an eBPF-based real-time monitoring tool for ECS workloads. While doing so, he intercepted communication between the ECS agent and AWS backend as part of his debugging process, which is when he noticed the undocumented WebSocket channel.

    From lowly tasks to privileged IAM roles

    Thanks to the default availability of IMDS, any container (with low-level access) on an EC2-based ECS instance can read the instance role credentials intended for the ECS agent.

    β€œNo container breakout (no hostroot access) was required – however IMDS access was required via clever network and system trickery from within the container’s own namespace,” Haziz noted, adding that accessing IMDS lets any container impersonate an ECS agent. AWS has documentation on how to prevent or limit access to IMDS.

    Armed with those instance role credentials, the attacker can forge communication over the ACS WebSocket. This allows them to intercept or request IAM credentials of other running tasks, even if those tasks are supposed to be isolated by IAM roles. Essentially, the compromised container escalates by masquerading as the orchestrator ECS agent responsible for managing and orchestrating tasks.

    β€œThe stolen keys (IAM credentials) work exactly like the real task’s keys,” Haziz said. β€œAWS CloudTrail will attribute API calls to the victim task’s role, so initial detection is tough – it appears as if the victim task is performing the actions.” This lets attackers be invisible in the logs because AWS thinks the victim is doing everything.

    AWS Breaking containers ECS ECScape flaw hijack IAM lets roles
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHerman Miller’s surprise sale slashes prices by 25% – and these are the office chair deals I’d buy for your home and office
    Next Article Stargate’s slow start reveals the real bottlenecks in scaling AI infrastructure
    Techurz
    • Website

    Related Posts

    Opinion

    Robinhood to list a fund that lets anyone back Y Combinator startups

    August 5, 2026
    Opinion

    AWS is helping vibe-coding startup Superblocks, and the implications are big

    August 3, 2026
    Opinion

    Why these startup CEOs don’t think AI will replace human roles

    February 19, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.