CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Companies

AWS IoT and Device Defender: Critical Policy Misconfiguration

July 16, 2026

AWS IoT's Device Defender service includes an audit check (IOT_POLICY_OVERLY_PERMISSIVE_CHECK) that flags overly permissive policies granting publish/subscribe on $aws/things/*. This misconfiguration, rated critical by AWS, allows a compromised certificate to read or modify device shadows, jobs, and job executions for all devices in the fleet. The Shark vacuum vulnerability exploits this exact issue.