A further note on the S3 technique described: It's also extremely useful as an attacker to turn on S3 dataevents (in CloudTrail) for a bucket you take over, since they will cost your victim 20x as much money as the request that creates the event log.
A note on the s3 technique described. It’s also extremely useful, as a researcher, to turn on bucket logs or s3 dataevents for a bucket you takeover. You can then build out the prefixes that pre-existed and do all sorts of interesting things. Checkmarx likely did this as well