logo

S3 Security Is Flawed By Design | UpGuard

ID: 5ad148be-2f96-5a0d-a14e-4dcfda13abe7

STIX ID: report--5ad148be-2f96-5a0d-a14e-4dcfda13abe7

Feed Name: UpGuard Blog

Threat Score
65/100

Date Published: 2024-09-10

Date Updated: 2026-05-01

...
...

UpGuard details a persistent, large-scale problem of Amazon S3 misconfiguration that has led to thousands of exposed buckets and tens of millions of breached records. The report highlights two primary root causes— the misleading "any authenticated users" permission and the confusing interaction between ACLs and bucket policies—argues that AWS' incremental controls (like Block Public Access) reduce but do not eliminate risk, and recommends more fundamental product changes, such as separating public web hosting storage from always-private storage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.