Thousands Of Exposed AWS Keys Remain Active Arabian Post
Security researchers examining AWS credentials exposed between August 2022 and August 2026 re-tested 10,616 complete key pairs on August 10. Some 9,308, or about 88%, still authenticated successfully, pointing to a persistent failure by organisations and developers to revoke cloud credentials after they become publicly accessible.
The investigation identified 431,875 AWS secrets across publicly accessible material, which were reduced after deduplication to 64,024 unique keys associated with 50,654 AWS accounts. Credentials appeared in code repositories, historical Git commits, datasets, Docker images, software registries and continuous integration logs, illustrating how secrets can survive far beyond the files or projects in which they were initially placed.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment