logo

Here’s all the ways an abandoned cloud instance can cause security issues

ID: 33632a08-1845-5112-a189-525f3dcd65bb

STIX ID: report--33632a08-1845-5112-a189-525f3dcd65bb

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2025-02-04

Date Updated: 2026-04-21

Author: Greg Otto

...
...

watchTowr researchers found that hundreds of neglected or deleted AWS S3 buckets — some dating back years — could be reclaimed and were still being referenced by numerous government, corporate, and software systems, receiving over 8 million HTTP requests; this exposed routes for potential large-scale supply-chain, update, and VM/image-based compromises (examples include CISA advisory files, SSL VPN configs, and Vagrant-sourced VM images). The report highlights systemic risk from abandoned cloud resources, documents affected sectors, and states AWS sinkholed the infrastructure after notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.