Wildcard Resources for Sensitive Actions
IAM policies grant data-exfiltration actions like s3:GetObject, secretsmanager:GetSecretValue, and ssm:GetParameter with Resource: '*'. This allows principals to read sensitive data from any resource in the account, violating least-privilege principles.