“Since AWS prohibited using the management account as the hub, customers were forced to deploy the hub in a less secure account - often a development, sandbox, or similarly low-sensitivity account.”
AWS built a tool to audit risky cross-account access and told customers to deploy it outside the management account. That opened a path from sandbox accounts into production. AWS only changed the docs. Existing deployments stay exposed until customers find them.