logo

Hundreds of leaked AWS keys give full control over corporate accounts

ID: ffeb02d7-b8d7-5be4-aa8e-5937b1814328

STIX ID: report--ffeb02d7-b8d7-5be4-aa8e-5937b1814328

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Bill Toulas

...
...

Executive summary: Truffle Security found more than 9,300 active AWS access keys publicly exposed across code repositories, Docker images, registries, CI logs and other sources between August 2022 and August 2026, including thousands linked to corporate accounts; many keys possess AdministratorAccess or root privileges (including 526 root keys and a significant subset with full account control), a large number remain valid and unrotated, and the largest single source of leaks was Hugging Face. The exposure enables full account takeover risks — data exfiltration, service disruption, creation of rogue admin accounts, and cryptomining — and the report recommends deleting root keys, rotating or revoking exposed credentials, reviewing IAM by age, and configuring budget alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.