Tuesday, 02 January 2024 12:17 GMT

Thousands Of Exposed AWS Keys Remain Active Arabian Post


(MENAFN- The Arabian Post) clearfix"> More than 9,300 Amazon Web Services access keys exposed publicly over four years remained usable this month, including hundreds capable of giving an intruder unrestricted control of corporate cloud accounts.

Security researchers examining AWS credentials exposed between August 2022 and August 2026 re-tested 10,616 complete key pairs on August 10. Some 9,308, or about 88%, still authenticated successfully, pointing to a persistent failure by organisations and developers to revoke cloud credentials after they become publicly accessible.

The investigation identified 431,875 AWS secrets across publicly accessible material, which were reduced after deduplication to 64,024 unique keys associated with 50,654 AWS accounts. Credentials appeared in code repositories, historical Git commits, datasets, Docker images, software registries and continuous integration logs, illustrating how secrets can survive far beyond the files or projects in which they were initially placed.

MENAFN27082026000152002308ID1111584609



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story