logo

Researchers Uncover Thousands of Leaked AWS Keys

ID: 223a99fb-5f65-5092-a3c1-fb3401626dd1

STIX ID: report--223a99fb-5f65-5092-a3c1-fb3401626dd1

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

...
...

Truffle Security found tens of thousands of publicly exposed AWS key pairs across git history, Hugging Face datasets, Docker images and CI logs; 10,616 key pairs had complete credentials, 88% still authenticated, and 768 corporate keys had full admin/root rights. Many keys were old and never rotated, most accounts lack budget alerts (increasing risk of unnoticed cryptomining or data theft), and the report urges deleting root keys, sorting IAM keys by age, setting budget alarms, treating exposed secrets as compromised, and monitoring for AWSCompromisedKeyQuarantine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.