Enterprise Config Traps
A searchable catalogue of dangerous defaults, brittle infrastructure patterns, and production-grade configuration failures that hide in ordinary enterprise platforms.
Active Threat Records
178 RECORDSAggregated ClusterRole Labels Silently Grant Unreviewed RBAC Permissions
A ClusterRole label that happens to match an existing aggregation selector silently folds its rules into a trusted aggregate role, granting permissions no reviewer approved.
An AWS Principal Field Left as an Account ARN Silently Grants Every Role in That Account
An S3 bucket policy Principal set to an account-root ARN grants access to every IAM identity in that account, not just the intended role, creating a silent and growing exposure.
Zone Aging Enabled Without Server Scavenging Silently Preserves Stale AD DNS Records
Enabling zone aging in Active Directory-integrated DNS without also enabling server-level scavenging leaves stale records permanently in place, silently misdirecting name resolution.
A Pod Security Admission Namespace Label That Silently Waives Enforcement
A namespace's Pod Security Admission enforce label looks protective, but a forgotten cluster-wide exemption silently overrides it, letting privileged pods run unblocked.
Federated Credential Audience Mismatch Silently Blocks Azure Workload Identity Token Exchange
An Entra ID federated identity credential can be created with no errors while its audience field never matches the workload's actual OIDC token, causing silent, indefinite Azure AD authentication failure.
A Namespace Exemption Label That Lets Privileged Pods Bypass Admission Control
A namespace label intended to enforce restricted Pod Security Admission was silently overridden by a bulk relabelling script and an audit-only custom admission policy, letting privileged pods run undetected.
DMARC pct Left Unset Silently Caps Enforcement at Zero Despite a p=reject Policy
A DMARC record using p=reject with pct omitted relies on a specification default that some mail paths do not honour identically to an explicit value, leaving spoofed mail delivered while aggregate reports look clean.
RDS Security Group Rule Referencing a Shared SG Lets All Its Members Reach the Database
An RDS rule that allows traffic from a security group ID looks tightly scoped but silently grants access to every future member of that shared group.
A CloudTrail Trail Marked 'Logging' That Silently Excludes Data Events
A CloudTrail trail can report IsLogging true while data events for S3 and Lambda remain fully disabled, leaving no forensic record of object access or function invocations despite an apparently healthy trail status.
A Namespace Label Typo That Lets Pod Security Admission Silently Allow Privileged Pods
A misspelled Pod Security Admission enforce label passes kubectl apply but leaves the namespace fully unprotected, because Kubernetes only validates label syntax, not the PSA vocabulary.
Removed Authenticated Users From a GPO's Security Filter and Broke Policy Delivery
Removing Authenticated Users from a GPO's security filter to scope delivery silently blocks policy application on computers unless the replacement group explicitly holds Apply Group Policy rights.
A CAA Record Missing the Renewal CA Silently Blocks Certificate Issuance
A CAA record naming only the original CA silently blocks renewal or failover issuance from any additional CA, even though prior issuance succeeded and the domain appears correctly configured.