Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

August 24, 2026

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

August 24, 2026

Researchers Uncover Thousands of Leaked AWS Keys

August 24, 2026
Facebook X (Twitter) Instagram
Monday, August 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Researchers Uncover Thousands of Leaked AWS Keys
Cyber Security

Researchers Uncover Thousands of Leaked AWS Keys

Team-CWDBy Team-CWDAugust 24, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights.

Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging Face datasets, Docker images, package registries and CI logs.

“We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month’s spend,” the security vendor continued.

“No key material is published, and every owner we could identify is being notified.”

Of the 10,616 pairs, 88% still authenticate. They include 768 corporate AWS keys which have full admin rights, Truffle Security said.

Read more on AWS keys: CISA Details Incident Response to Exposed AWS GovCloud Keys

AWS account takeover could allow malicious actors to steal or delete critical cloud data, or even covertly install cryptocurrency mining software to monetize access that way.

Only 9.5% of keys had a budget alert set up which would flag this kind of activity, the report claimed.

Hugging Face was the largest single source of leaked keys, with 8482 unique live keys discovered across 3394 public datasets – 18% of which had root privileges.

For live keys with creation dates, the median age was around five years, although the oldest was over 17 years.

“Rotation is the rarer event,” the report continued. “Of the keys where we could enumerate the user’s access keys, only 13.7% (398 of 2903) have any newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up.”

Steps to Reduce the Risk of Leaked AWS Keys

Truffle Security urged organizations and individuals to improve key handling in order to minimize security risk, sharing the following advice:

  • Delete root access keys, checking every account, including personal ones. The report claimed one in six leaked keys had root privileges
  • Sort IAM keys by age using “aws iam list-access-keys” plus a maximum age policy
  • Set a budget alarm to catch crypto-mining early. Even a $10 alert would be better than nothing, given that 90.5% of leaked-key accounts have no alert set up
  • Treat exposed secrets as permanently compromised: 43% of those discovered by the researchers appeared more than once across repos, datasets, and images
  • Watch for the quarantine policy: If AWS attaches “AWSCompromisedKeyQuarantine” to a user, it is saying that the key is public



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Next Article One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Team-CWD
  • Website

Related Posts

Cyber Security

What the Recent Restrictions on Anthropic Mean for Organizations Adopt

August 21, 2026
Cyber Security

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

August 20, 2026
Cyber Security

How Borussia Dortmund’s IT Chief Makes the Case for Cybersecurity

August 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Drowning in spam or scam emails lately? Here’s why

January 27, 2026

2025’s most common passwords were as predictable as ever

January 21, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.