Cloud Security Attacking AWS STS, AssumeRole, and Cross-Account Trust How sts:AssumeRole, weak trust policies, and missing ExternalId enable cross-account pivots, plus blue-team detection. 2025.09.26 Cloud Security