AWS IoT's device shadow service is central to the Shark vacuum vulnerability. The Exec_Command field in the shadow is processed by the device's management daemon, leading to remote code execution. The misconfigured policy allows any certificate to publish/subscribe on all device topics, enabling cross-device attacks.