Skip to main content
Daily Risk Register

Enterprise Config Traps

A searchable catalogue of dangerous defaults, brittle infrastructure patterns, and production-grade configuration failures that hide in ordinary enterprise platforms.

/

Active Threat Records

178 RECORDS
Kuberneteshigh

Aggregated ClusterRole Labels Silently Grant Unreviewed RBAC Permissions

A ClusterRole label that happens to match an existing aggregation selector silently folds its rules into a trusted aggregate role, granting permissions no reviewer approved.

Inspect Trap and Fix
Amazon Web Serviceshigh

An AWS Principal Field Left as an Account ARN Silently Grants Every Role in That Account

An S3 bucket policy Principal set to an account-root ARN grants access to every IAM identity in that account, not just the intended role, creating a silent and growing exposure.

Inspect Trap and Fix
Active Directorymedium

Zone Aging Enabled Without Server Scavenging Silently Preserves Stale AD DNS Records

Enabling zone aging in Active Directory-integrated DNS without also enabling server-level scavenging leaves stale records permanently in place, silently misdirecting name resolution.

Inspect Trap and Fix
Kuberneteshigh

A Pod Security Admission Namespace Label That Silently Waives Enforcement

A namespace's Pod Security Admission enforce label looks protective, but a forgotten cluster-wide exemption silently overrides it, letting privileged pods run unblocked.

Inspect Trap and Fix
Microsoft Azuremedium

Federated Credential Audience Mismatch Silently Blocks Azure Workload Identity Token Exchange

An Entra ID federated identity credential can be created with no errors while its audience field never matches the workload's actual OIDC token, causing silent, indefinite Azure AD authentication failure.

Inspect Trap and Fix
Kuberneteshigh

A Namespace Exemption Label That Lets Privileged Pods Bypass Admission Control

A namespace label intended to enforce restricted Pod Security Admission was silently overridden by a bulk relabelling script and an audit-only custom admission policy, letting privileged pods run undetected.

Inspect Trap and Fix
DNShigh

DMARC pct Left Unset Silently Caps Enforcement at Zero Despite a p=reject Policy

A DMARC record using p=reject with pct omitted relies on a specification default that some mail paths do not honour identically to an explicit value, leaving spoofed mail delivered while aggregate reports look clean.

Inspect Trap and Fix
Amazon Web Serviceshigh

RDS Security Group Rule Referencing a Shared SG Lets All Its Members Reach the Database

An RDS rule that allows traffic from a security group ID looks tightly scoped but silently grants access to every future member of that shared group.

Inspect Trap and Fix
Amazon Web Serviceshigh

A CloudTrail Trail Marked 'Logging' That Silently Excludes Data Events

A CloudTrail trail can report IsLogging true while data events for S3 and Lambda remain fully disabled, leaving no forensic record of object access or function invocations despite an apparently healthy trail status.

Inspect Trap and Fix
Kuberneteshigh

A Namespace Label Typo That Lets Pod Security Admission Silently Allow Privileged Pods

A misspelled Pod Security Admission enforce label passes kubectl apply but leaves the namespace fully unprotected, because Kubernetes only validates label syntax, not the PSA vocabulary.

Inspect Trap and Fix
Active Directoryhigh

Removed Authenticated Users From a GPO's Security Filter and Broke Policy Delivery

Removing Authenticated Users from a GPO's security filter to scope delivery silently blocks policy application on computers unless the replacement group explicitly holds Apply Group Policy rights.

Inspect Trap and Fix
DNShigh

A CAA Record Missing the Renewal CA Silently Blocks Certificate Issuance

A CAA record naming only the original CA silently blocks renewal or failover issuance from any additional CA, even though prior issuance succeeded and the domain appears correctly configured.

Inspect Trap and Fix