Callback-url-http-3a-2f-2f169.254.169.254-2flatest-2fmeta Data-2fiam-2fsecurity Credentials-2f __top__ -

This is not a theoretical risk. Several high-profile incidents and campaigns have exploited this exact chain.

: First, an EC2 instance is launched with an IAM role attached. This IAM role defines the permissions the instance has to access AWS resources. This is not a theoretical risk

Recommended actions: