Hundreds of leaked AWS keys give full control over corporate accounts
Research found over 9,300 publicly leaked AWS access keys still active after up to four years, exposing a systemic failure in cloud credential lifecycle management that could grant attackers full account control.
Summary written by editorial AI · Source link below
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Editorial Analysis
Thousands of long-lived, publicly exposed AWS keys remaining valid for years means attackers have a low-effort path to full cloud account compromise—a problem likely present in many European enterprises' environments.
Scan for exposed AWS keys across all repositories and public surfaces, rotate all long-lived access keys to short-lived role-based credentials, and enforce automated rotation policies.
Thousands of publicly leaked cloud access keys remain active for years—verify your organisation's cloud credential hygiene to prevent account takeover.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at BleepingComputer in a new tab.
More from the Cloud Desk
- Securing Filesystems for Confidential Computing21 Aug
- AWS Network Firewall now supports rule hit count20 Aug
- RetryGuard: Preventing Self-Inflicted and Attack-Driven Retry Storms in Cloud Applications19 Aug
- Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway18 Aug
- How to Spot and Stop Rogue Device Joins18 Aug