How could a zero day web vulnerability lead to a near complete compromise within an AWS environment? Pretty easily actually. While the SugarCRM CVE-2023-22952 0-day authentication bypass and remote code execution vulnerability might seem like a typical zero day, the infrastructure behind the scenes of the web application causes the most concern and potential for mayhem if not secured correctly. When a threat actor shows clear signs of AWS knowledge, the sky's the limit for what they can accomplish if they have the right permissions. This presentation maps out various attacks against AWS environments following the MITRE ATTACK Matrix framework, wrapping up with the multiple prevention mechanisms an organization can put in place to protect themselves. The complexity of these attacks details how seemingly innocuous AWS API calls lead to much more daunting activity that is not always traceable. One size does not fit all in cloud security, but these attacks highlight key areas to focus on to make sure you're ready to defend against those attacks when they come.