February Recap: New AWS Sensitive Permissions

2 mins to read

As February 2025 wraps up, we’re back with the latest updates on AWS sensitive permissions, newly supported services, and regional expansions. Keeping up with these changes is critical for securing cloud environments and ensuring that high-risk permissions are properly governed. This month, we’ve identified new sensitive permissions across multiple AWS services, highlighting potential security implications that teams should be aware of. Read on for a full breakdown of what’s new and what it means for your cloud security strategy.

Existing Services with New Sensitive Permissions

Amazon Simple Email Service

Service Type: Customer Engagement

Permission: ses:StartAddressListImportJob

  • Action: Grants permission to start an import job on an address list
  • Mitre Tactic: Defense Evasion
  • Why it’s sensitive: Enables bulk email list imports, which could be misused.

Permission: ses:RegisterMemberToAddressList

  • Action: Grants permission to add a member to an address list
  • Mitre Tactic: Defense Evasion
  • Why it’s sensitive:  Allows adding email addresses to predefined lists, which could be exploited.  

AWS CloudFormation

Service Type: Infrastructure Management

Permission: cloudformation:ExecuteStackRefactor

  • Action: Grants permission to execute a stack refactor
  • Mitre Tactic: Defense Evasion
  • Why it’s sensitive: Can be used to shift resources somewhere else, allowing unauthorized changes to infrastructure.

AWS Amplify

Service Type: Development and DevOps tools

Permission: amplify:DisassociateWebACL

  • Action: Grants permission to disassociate a WebACL from a resource
  • Mitre Tactic: Defense Evasion
  • Why it’s sensitive: Allows detaching a Web Application Firewall (WAF) from an AWS Amplify app, potentially exposing the application to security threats.

Conclusion

As AWS continues to introduce new permissions and expand its services, managing cloud security becomes increasingly complex. This month’s updates highlight how even seemingly routine permissions—like email list management, infrastructure refactoring, and security control removal—can introduce risks if left unchecked. Without proper oversight, organizations face potential data leaks, security control bypasses, and unauthorized infrastructure changes that could go unnoticed.

Sonrai Security addresses these challenges with our Cloud Permissions Firewall, enabling security teams to automate the detection, restriction, and monitoring of sensitive permissions across AWS environments. By continuously enforcing least privilege and providing real-time visibility into evolving permission risks, we help organizations stay ahead of threats without disrupting operations.

Sonraí Security banner with text: "Secure the Most Sensitive Cloud Permissions... with one click." Purple sky and white clouds background.

Find next month’s recap here.

Author

Karen Levy

Karen Levy

Karen Levy is the Vice President of Product Marketing at Sonrai Security, where she leads product positioning, strategic messaging, and go-to-market execution for the enterprise cloud security platform. With more than 15 years of cybersecurity product marketing experience, Karen has held leadership roles at industry-recognized organizations including RSA, CyberArk, and Recorded Future, bringing deep expertise in cloud identity, access, and security solutions to her work. At Sonrai, Karen champions clarity and actionable insight in cloud security, helping practitioners and leaders navigate complex access and permissions challenges. Her writing focuses on practical strategies for securing modern cloud environments, and she regularly contributes thought leadership on emerging trends in cloud permissions and privileged access management. Karen holds a BA in Chemistry from the University of Pennsylvania and an MBA from Boston University’s Questrom School of Business, and she brings a blend of business acumen and technical understanding to her work.

Vice President Product Marketing

LinkedIn