More than 9,300 Amazon Web Services (AWS) access keys that were publicly exposed between August 2022 and August 2026 are still active and valid, according to a recent report by Bleeping Computer.Truffle Security has been tracking this exposure for four years, finding that 817 of the exposed keys were linked to companies, with 526 being AWS root keys. Researchers noted that 242 keys were associated with Identity and Access Management (IAM) users holding the AdministratorAccess policy, granting full permissions across AWS services. The company identified 431,875 AWS secrets in various code repositories and extracted 64,024 unique AWS keys. Of the 10,616 keys with verifiable credentials, 88% remained active as of August 10.Hugging Face, a platform for AI models, was the largest source of leaked keys, with 8,482 exposures. Many of these keys were old, with a median age of about five years, and had likely never been rotated. Full control of an AWS account could allow attackers to exfiltrate data, take control of applications, or deploy cryptominers. Truffle Security recommends deleting root access keys, reviewing IAM credentials, rotating exposed keys, and configuring budget alerts.Source: Bleeping Computer
Cloud Security
Thousands of active AWS access keys remain publicly exposed
(Adobe Stock)
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
