Over 9,300 Amazon Web Services access keys have been publicly exposed since August 2022, with the majority still active and granting full account control. Security researchers warn that attackers could exploit these credentials to compromise corporate infrastructure.
A significant security breach has left thousands of AWS access keys exposed and functional. The leaked credentials, numbering more than 9,300, were discovered circulating publicly between August 2022 and August 2026, according to security research.
The access keys function as authentication credentials for AWS accounts. Each key pair consists of an access key ID and secret access key that grants programmatic access to cloud resources. With valid credentials, an attacker can provision new instances, access data stores, modify infrastructure, or extract sensitive information.
Current Status
Researchers have confirmed that the majority of exposed keys remain active. This extends the window of vulnerability significantly, as credentials have maintained their validity across multiple years. AWS has not automatically invalidated the compromised keys, placing responsibility on account owners to identify and revoke them.
Attack Surface
The exposure creates multiple attack vectors. Threat actors could use the credentials to:
- Launch infrastructure for cryptomining or botnet operations
- Access databases containing customer or proprietary information
- Modify or delete critical resources
- Establish persistent backdoors in corporate environments
- Incur substantial cloud hosting costs on victim accounts
Scope and Exposure
The leaked keys appear to have originated from multiple sources, including misconfigured repositories, exposed configuration files, and compromised development environments. Security teams across affected organizations may not be aware their credentials are public.
Recommended Actions
Organizations should immediately audit their AWS IAM logs for suspicious activity associated with any exposed keys. AWS recommends rotating all potentially compromised credentials and implementing automated credential rotation policies. Additionally, organizations should enforce multi-factor authentication and restrict IAM permissions using the principle of least privilege.
The incident underscores the critical importance of secrets management solutions and preventing credential exposure in version control systems and public repositories.
A security researcher discovered they had inadvertently captured phone call logs to military installations through a misconfigured system. The incident highlights infrastructure vulnerabilities in telecommunications routing.
Idaho National Laboratory is conducting a security review of Chinese lidar technology, with funding from companies in the electric and autonomous vehicle sectors. The investigation aims to identify potential vulnerabilities in the sensor systems.
Senator Ron Wyden has requested a comprehensive review of how federal agencies deploy hacking tools and spyware against Americans. The inquiry targets the FBI, DEA, ICE's Homeland Security Investigations, and the Secret Service.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies immediately patch two actively exploited vulnerabilities in TrueConf Server, a self-hosted communications platform.