⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

AWS IoT: Device Shadow and Policy Misconfiguration

July 16, 2026

AWS IoT's device shadow service is central to the Shark vacuum vulnerability. The Exec_Command field in the shadow is processed by the device's management daemon, leading to remote code execution. The misconfigured policy allows any certificate to publish/subscribe on all device topics, enabling cross-device attacks.