Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket
ID: a422837b-eb84-50bb-b5f2-5d3542736955
STIX ID: report--a422837b-eb84-50bb-b5f2-5d3542736955
Feed Name: The Register (Security)
Researchers uncovered an ongoing large-scale heist in which criminal gangs (linked to Nemesis and ShinyHunters) scanned roughly 26.8 million AWS IPs and used public tools to find exposed endpoints (env files, git repos, config files) to harvest AWS credentials, API keys, database and service secrets, and source code; attackers stored over 2 TB of stolen data in an open S3 bucket, with at least 1,526 AWS credentials identified as compromised in August and activity continuing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
