logo

TotalCloud Insights: Protect Your AWS Environment by Managing Access Keys Securely

ID: 784a85c2-1965-54bc-881b-a4dfd663c28b

STIX ID: report--784a85c2-1965-54bc-881b-a4dfd663c28b

Feed Name: Qualys Blog

Threat Score
50/100

Date Published: 2024-06-19

Date Updated: 2026-04-28

Author: Karan Ahuja

...
...

This report recounts an AWS access key theft investigation in which seven IAM access keys were compromised after being found on a publicly exposed Postman server; the attacker made SES-related API calls (GetSendQuota and UpdateAccountSendingEnabled) from unusual user agents and an atypical hosting-provider IP. The document describes detection indicators, remediation actions taken (credential rotation and key disablement), potential service impacts, recommended best practices for key management across cloud providers, and how Qualys TotalCloud can help identify and remediate such misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.