CISA’s disclosure about exposed AWS GovCloud credentials is a reminder that in cloud incidents, identity handling can matter more than the region name on the dashboard.