Cloud Security Nearly 20 billion files exposed in misconfigured cloud buckets May 29, 2026 Share By SC Staff Nearly 20 billion files, including sensitive credential and database dump files, have been exposed due to misconfigured cloud storage buckets. Mysterium VPN researchers discovered that 535,480 publicly accessible cloud storage buckets across major providers like Amazon S3, Google Cloud, Azure, DigitalOcean, and Alibaba contained these exposed files, accessible without any login or exploit, according to a recent report by Security Affairs. The exposed files encompass a wide range, with 685,047 credential and key files, such as .env files and private keys, and nearly 1 million database dumps, including .sql and .bak files. This level of exposure grants potential attackers direct access to live systems rather than just data. The research highlights that the danger lies not in individual files but in their interconnectedness, where a single misconfigured bucket can lead to a complete data breach. While Amazon S3 accounts for over two-thirds of the exposed storage, the issue stems from widespread misconfigurations by customers rather than platform insecurity. The report emphasizes that the solution involves defaulting to private settings, avoiding storing secrets in object storage, encrypting backups, and regularly scanning for vulnerabilities. For individuals, the advice includes using unique passwords, enabling multi-factor authentication, and limiting data sharing with services. Source: Security Affairs An In-Depth Guide to Cloud Security Get essential knowledge and practical strategies to fortify your cloud security. Learn More SC Staff Related API security Deleted Google API keys remain active for up to 23 minutes, study finds SC Staff May 21, 2026 While the Google Cloud Platform console indicates immediate deletion, researchers found that keys take an average of 16 minutes to become fully inactive, with the longest observed delay reaching 23 minutes. Cloud Security SASE manages your network access, but who manages your SASE? Anthony Lobretto May 19, 2026 SASE adoption is easier than ever, but expertise gaps still create major security and access risks. Cloud Security The hidden risk in hybrid IT: Fragmented vulnerability management Srikant Sreenivasan May 7, 2026 Hybrid IT and AI expand attack surfaces, making continuous, context-aware risk management essential. Related Events Cybercast Cloud Security: The AI Effect and How to Proceed On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Cloud Computing Greynet You can skip this ad in 5 seconds