AWS patched AppSync two months ago, a “confused proxy” vulnerability that allows attackers to impersonate other AWS tenants and use or hack other people’s AWS resources. This vulnerability was discovered and reported by security vendor Datadog in September, and it is located in AWS’s AppSync service.
