AWS Security Agent chains SQL Injection into autonomous login
Without any credentials provided, the agent extracted plaintext passwords via SQL Injection, guessed the TOTP secret, and logged in as admin. The docs say 'without credentials, only public pages' — but attack chains bypass that.